Impact
The flaw is an improper neutralization of special elements in SQL commands, which has been classified as CWE-89. It allows blind SQL injection through the New Simple Gallery plugin’s handling of user‑supplied input. An attacker can use this to read sensitive data from the database, and the nature of blind injection means the attacker would have to infer results from response timing or error messages, but no arbitrary code execution is possible based on the current description.
Affected Systems
All installations of the gopiplus New Simple Gallery plugin for WordPress with a version number of 8.0 or earlier are affected. Any WordPress site that has not upgraded beyond version 8.0 therefore remains vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity for this vulnerability. The EPSS score is less than 1%, suggesting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, involving crafted HTTP requests to the plugin’s endpoints that accept unfiltered input; authenticated access is not required.
OpenCVE Enrichment
EUVD