Impact
The Accordion Slider PRO plugin for WordPress contains a blind SQL Injection flaw, classified as CWE-89. An attacker can supply malicious input to the plugin’s storage routines, causing improperly sanitized data to be incorporated into an SQL command. This may allow the adversary to read, modify, or delete database information, resulting in confidentiality, integrity, and availability breaches for the affected WordPress site.
Affected Systems
The vulnerability applies to LambertGroup’s Accordion Slider PRO plugin versions that are 1.2 or older. In particular, any installation of the plugin from the first release up to and including version 1.2 is at risk.
Risk and Exploitability
The CVSS score of 8.5 places this flaw in the high severity range, indicating that exploitation carries substantial risk. The EPSS score is less than 1%, suggesting that, at present, the likelihood of real‑world exploitation is low, though the vulnerability is present in public code. It is not listed in the CISA KEV catalog, so no widespread active exploitation is reported. Attackers could likely trigger the injection via the plugin’s exposed hooks or settings pages, though the exact vector is not detailed in the CVE and must be inferred from typical WordPress plugin behavior.
OpenCVE Enrichment