Impact
This vulnerability allows attackers to execute blind SQL injection through the LambertGroup xPromoter top_bar_promoter plugin, enabling unauthorized access to sensitive data. The flaw arises from improper neutralization of special elements in an SQL command, classified as CWE‑89. Although the injection is blind, it permits manipulation of database queries without visible errors, potentially exposing confidential information.
Affected Systems
LambertGroup’s xPromoter WordPress plugin versions up to 1.3.4 are affected. No other vendors or versions are listed. Users running these versions should verify the plugin version and consider upgrading.
Risk and Exploitability
The vulnerability has a CVSS score of 8.5, indicating high severity, while the EPSS score is less than 1%, reflecting a low probability of exploitation in the wild. The plugin is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an attacker who can reach the plugin’s input fields—typically through authenticated or privileged site access—and construct SQL queries that exploit the input handling flaw. Because the injection is blind, the attacker may need to infer results via timing or other side‑channel techniques. The high severity warrants immediate remediation.
OpenCVE Enrichment