Impact
The vulnerability is an Improper Neutralization of Special Elements used in an SQL Command, classified as CWE-89, that allows blind SQL injection in the VanKarWai Lobo WordPress theme. Attackers could manipulate untrusted input to alter SQL queries, potentially extracting sensitive data or modifying database contents. The worst‑case impact is data compromise and, depending on the database environment, possible elevation of privileges or execution of arbitrary code if the injected payload is later interpreted as a statement with elevated rights.
Affected Systems
Affected are installations of the Lobo theme from VanKarWai, specifically versions from the first release through any version prior to 2.8.6. Any WordPress site using those theme versions is vulnerable unless the theme has been updated beyond the stated cutoff.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score of less than 1% suggests that the likelihood of a successful exploit is low but not impossible. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation at present. The attack vector is inferred to be via web‑based inputs processed by the theme—such as forum posts, comments, or custom forms—where malicious payloads can be injected into SQL queries.
OpenCVE Enrichment