Impact
Improper neutralization of special elements was found in Antideo Email Validator, allowing attackers to carry out blind SQL injection. The flaw permits an adversary to send crafted input into the plugin’s email validation routine, causing the application to embed unsanitized data into database queries. Successful exploitation can lead to unauthorized data retrieval, modification, or deletion, compromising the website’s confidentiality, integrity, and availability. The weakness corresponds to CWE-89.
Affected Systems
The vulnerability exists in the Antideo Email Validator plugin for WordPress from earlier unknown versions through 1.0.10 inclusive. Users who have not applied an update beyond 1.0.10 remain affected.
Risk and Exploitability
The CVSS score is 7.5, indicating a moderate‑to‑high severity. The EPSS score is below 1%, suggesting low but non‑zero probability of exploitation in the wild. The issue is not yet listed in CISA’s KEV catalog. The most likely attack vector is a remote attacker submitting malicious data via the plugin’s email validation form on a publicly accessible WordPress site. No specific environment or credential prerequisites are stated, so the vulnerability is presumed to be exploitable by unauthenticated users who can interact with the plugin’s interface.
OpenCVE Enrichment