Impact
don-themes Riode Core plugin contains an improper neutralization of special elements used in an SQL command. The flaw, identified as a blind SQL injection (CWE-89), permits an attacker to inject malicious queries into the database. Depending on the database privileges granted to the application, the attacker could extract sensitive data, modify records, or in worst‑case scenarios, execute arbitrary commands on the underlying server.
Affected Systems
The vulnerability affects Riode Core for WordPress from unknown initial releases through version 1.6.26. Any website that is running a version of the plugin up to and including 1.6.26 is at risk. The affected product is provided by don‑themes and is commonly used as a theme framework for WordPress sites.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as critical. The EPSS indicates a very low likelihood of exploitation (less than 1%), and it is not yet listed in the CISA KEV catalog. Nonetheless, a blind SQL injection can be performed remotely via crafted HTTP requests to the plugin’s administrative or front‑end endpoints. Attackers need no special credentials; they only require the ability to inject payloads into the plugin’s query parameters. Given the potential for data exfiltration, the risk for affected sites remains significant.
OpenCVE Enrichment