Impact
The vulnerability arises from improper neutralization of special elements in SQL commands, permitting a blind SQL injection against the TeconceTheme Emerce Core plugin. An attacker can craft input that is not correctly sanitized, which may allow extraction of sensitive data from the WordPress database. The impact includes unauthorized disclosure of data, as indicated by the CWE-89 classification. Based on the description, it is inferred that no direct data modification capability is reported, though the nature of SQL injection could enable further exploitation once data is accessed.
Affected Systems
WordPress sites running the Emerce Core plugin from unspecified earlier releases up through version 1.8 are affected. The issue is tied to the TeconceTheme Emerce Core product, and any installation of these versions on a live site is vulnerable.
Risk and Exploitability
The CVSS base score of 9.3 reflects a high severity, while the EPSS score of less than 1% indicates a low likelihood of immediate exploitation. The vulnerability is not currently listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Although the CVE data does not explicitly describe the attack vector, it is inferred that the vulnerability is exploitable via remote web-based requests to the vulnerable plugin endpoint, allowing the blind SQL injection.
OpenCVE Enrichment