Impact
The vulnerability is an SQL injection flaw in the Golemiq 0 Day Analytics WordPress plugin, stemming from improper neutralization of special elements used in SQL commands. Attackers could inject malicious SQL statements, potentially enabling unauthorized read or modification of the site’s underlying database. This weakness corresponds to CWE‑89.
Affected Systems
All WordPress sites that have installed the Golemiq 0 Day Analytics plugin with a version up to and including 4.0.0 are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. The EPSS score of less than 1 % suggests that exploitation in the wild is currently uncommon, and the vulnerability is not listed in the CISA KEV catalog. The plugin’s exposed inputs are the likely attack surface. The CVE description does not specify whether authentication is required; it is inferred that remote attackers may be able to exploit the flaw by sending crafted requests through the plugin’s interface, but the exact prerequisites remain unclear.
OpenCVE Enrichment