Impact
The ZIP Code Based Content Protection plugin for WordPress up to version 1.0.0 contains an SQL injection vulnerability that allows an attacker to insert arbitrary SQL statements into queries. This weakness, identified by CWE‑89, can enable the attacker to read sensitive data from the database, modify content, or even delete records, thereby compromising the confidentiality and integrity of the site’s information.
Affected Systems
The affected component is the PressTigers ZIP Code Based Content Protection plugin. All installations using version 1.0.0 or earlier are potentially vulnerable, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 7.6 places this issue in the high severity range. The EPSS score of less than 1% indicates that the observed exploitation probability is very low at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote and requires sending crafted HTTP requests to the plugin’s input handling mechanism, possibly from an unauthenticated or low‑privilege user. Though exploitation is theoretically possible, real‑world evidence of exploitation remains limited.
OpenCVE Enrichment
EUVD