Impact
The Nestbyte Core WordPress plugin contains an improper neutralization of SQL special elements (CWE-89) that permits blind SQL injection. Attackers can supply crafted input that is incorporated directly into database queries, enabling them to read sensitive data or alter database records. The vulnerability does not claim or provide any direct remote code execution capability; the impact is confined to the database layer.
Affected Systems
TeconceTheme’s Nestbyte Core plugin is affected for every release from the earliest available version up to and including 1.2. Any installation of the plugin at or below version 1.2 is considered vulnerable.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity assessment. The EPSS score of less than 1% indicates a very low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The weakness can be exercised through web input that passes unsanitized data to the database; the description does not specify authentication requirements, so the attack path is likely via publicly exposed plugin endpoints. While the exploitation does not elevate to code execution, it could still compromise confidentiality and integrity of the site’s data.
OpenCVE Enrichment