Impact
The vulnerability is an SQL injection flaw caused by improper neutralization of special elements in SQL commands. An attacker can craft blind SQL queries through the plugin’s input mechanisms to extract sensitive data or alter database contents, resulting in a compromise of data confidentiality and integrity.
Affected Systems
The issue affects the WordPress Coven Core plugin distributed by TeconceTheme, for all releases up to and including version 1.3. Any WordPress site still running that plugin version is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 denotes a severe threat, while the EPSS score of <1% indicates that exploitation is currently low‑probability and the vulnerability has not been listed in CISA KEV. An attacker would target the plugin’s input endpoints, sending crafted payloads that bypass the lack of sanitization and execute arbitrary SQL commands.
OpenCVE Enrichment