Impact
TeconceTheme Saasplate Core contains an SQL injection flaw that allows an attacker to inject malicious SQL statements into database queries. The vulnerability manifests as a blind injection, enabling the attacker to infer database content and potentially extract sensitive information such as usernames, passwords, and other stored data. The primary impact is unauthorized data exposure with the potential for further compromise of the WordPress site.
Affected Systems
The flaw affects the Saasplate Core plugin distributed by TeconceTheme, affecting all installed versions up to and including 1.2.8. Systems running these versions are susceptible unless the plugin is removed or patched.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not cataloged in CISA’s KEV list. Based on the description, the attack vector is likely remote via the web interface that hosts the plugin, and authentication requirements are not specified, implying the attack could be carried out against publicly accessible instances. An attacker could send crafted SQL queries to the vulnerable endpoint and, through blind inference techniques, retrieve database contents.
OpenCVE Enrichment