Impact
An SQL Injection vulnerability exists in the Themeisle WP Full Stripe Free plugin when it attempts to construct SQL queries without proper neutralization of special characters. A malicious attacker can exploit this flaw to read, modify, or delete database records, potentially compromising confidentiality and integrity of the site’s data and affecting the entire WordPress installation.
Affected Systems
WordPress sites that run the Themeisle WP Full Stripe Free plugin version 8.2.5 or older are affected. The issue applies to all installations using any of those vulnerable plugin releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.6, indicating high severity. The EPSS score is below 1%, suggesting that the probability of exploitation is low at present, and it has not been listed in the CISA KEV catalog. Attackers can likely reach the vulnerability via the plugin’s user-facing interfaces, meaning the attack vector is remote, but the lack of high exploit prevalence reduces immediate risk.
OpenCVE Enrichment
EUVD