Impact
The vulnerability arises from improper neutralization of special elements within SQL commands in the Ultra Portfolio plugin. This blind SQL injection flaw enables an attacker to inject arbitrary SQL via the plugin’s interface, potentially leading to unauthorized data extraction, modification, or deletion. The weakness is classified as CWE‑89.
Affected Systems
The issue affects the Ultra Portfolio plug‑in from themepassion version 6.7 and earlier. Users running any of those versions on their WordPress sites are susceptible.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score below 1% suggests currently low exploitation likelihood. The vulnerability is not listed in CISA KEV. The attack vector is likely remote, exploiting a web interface of the plug‑in; an attacker would need to craft specially crafted requests to the plug‑in’s endpoints, with no authentication explicitly required in the description, but the exact prerequisites are not detailed.
OpenCVE Enrichment