Impact
The vulnerability permits untrusted input to be incorporated into an SQL statement without proper neutralization, enabling an attacker to inject and execute arbitrary SQL commands. The potential impact includes unauthorized data disclosure, data modification, or deletion within the WordPress database.
Affected Systems
The flaw affects the Saad Iqbal AppExperts plugin for WordPress for all releases up to version 1.4.5. WordPress sites that have this plugin installed and are running a vulnerable version are at risk.
Risk and Exploitability
The CVSS score of 8.5 categorises this as high severity, and the EPSS score indicates a very low but non‑zero probability of exploitation in the wild; it is not currently listed in the CISA KEV catalog. The likely attack vector is remote: an adversary can supply malicious data through the plugin’s input interface over the web. Exploitation requires only that the attacker can reach the vulnerable endpoint, making it broadly accessible to anyone with web access to the site.
OpenCVE Enrichment