Impact
The CleverReach WP plugin for WordPress is vulnerable up to version 1.5.20 to time‑based SQL injection through its title parameter. Insufficient escaping and lack of query preparation allow an unauthenticated attacker to append arbitrary SQL to the existing query and pull sensitive information from the database. This is a classic SQL Injection weakness (CWE‑89) with the primary impact of data exfiltration.
Affected Systems
All installations of the CleverReach WP plugin for WordPress with versions 1.5.20 or earlier are affected. Updated or newer versions are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating low current exploitation probability but still a significant risk. Attackers can exploit the flaw by sending a crafted request containing a malicious title value to the article search endpoint without authentication; a time‑based response confirms successful injection. No public exploits have been documented at this time.
OpenCVE Enrichment
EUVD