Impact
A flaw in the Coupon API WordPress plugin permits authenticated administrators to inject arbitrary SQL through the log_duration parameter. The insufficient escaping and lack of prepared statements enable the attacker to append new queries to the existing statement, potentially exposing sensitive database contents. This vulnerability directly affects the confidentiality of data stored in the WordPress database.
Affected Systems
The vulnerability applies to all releases of the Coupon API plugin up to and including version 6.2.12. The affected product is managed by kamilkhan and is used as a WordPress plugin. No further sub‑version details are provided.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity and the EPSS score of less than 1% shows a very low current exploitation probability. Because the flaw requires Administrator‑level authentication, the attack surface is limited to privileged users, and it is not listed in CISA’s KEV catalog. Exploitation would involve logging in as an administrator, sending a crafted request containing malicious SQL in the log_duration field, and capturing the resulting data leak.
OpenCVE Enrichment
EUVD