Impact
The Vibes WordPress plugin contains a time‑based SQL Injection flaw in the ‘resource’ parameter. Insufficient escaping and lack of prepared statements allow unauthenticated attackers to append malicious SQL clauses to existing queries, enabling extraction of sensitive data from the database. This vulnerability is classified as CWE‑89.
Affected Systems
All versions of the Vibes plugin from pierrelannoy up to and including 2.2.0 are affected. Users running any of these releases on a WordPress site are susceptible to the exploit.
Risk and Exploitability
The CVSS score is 7.5, reflecting a high severity. The EPSS score of less than 1% suggests exploitation is currently uncommon, and the vulnerability is not listed in the CISA KEV catalog. Attackers can target the vulnerable parameter directly from the web interface without authentication, making it a web‑based injection that can be triggered by any visitor to the site.
OpenCVE Enrichment
EUVD