Impact
TeconceTheme Uroan Core contains an improper neutralization of special elements used in SQL commands. This flaw enables blind SQL injection, allowing an attacker to query or modify the database without needing direct feedback. The weakness is identified as CWE‑89 and can lead to unauthorized data exfiltration or manipulation of application data.
Affected Systems
The vulnerability affects the Uroan Core WordPress plugin from its inception up through version 1.4.4. Users running any build of the plugin at or below that level are impacted; newer plugin builds are not affected as documented by the CNA.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score is below 1 %, suggesting exploitation is possible but unlikely in the wild at present. The lack of KEV listing means no known mass exploitation at the time of this analysis, but the flaw can be exploited remotely through the WordPress front‑end or admin interface that processes plugin input. An attacker would need to craft payloads targeting the vulnerable database queries to extract or modify data, requiring only standard web access privileges.
OpenCVE Enrichment