Impact
The vulnerability arises from improper neutralization of special elements in an SQL command, allowing blind SQL injection within the BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin. An attacker could extract or modify sensitive data stored in the WordPress database, potentially leading to confidentiality or integrity breaches. The flaw stems from insufficient input validation (CWE‑89) and, if exploited successfully, could provide an attacker with unauthorized database access.
Affected Systems
The affected product is VillaTheme’s BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin, deployed within WordPress sites. Versions up to and including 1.0.28 are vulnerable. Users running any of these releases, regardless of whether the plugin is used heavily or minimally, are at risk unless patched.
Risk and Exploitability
With a CVSS score of 8.5, this issue is considered High severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, suggesting no known public exploitation yet. The attack is likely carried out via specially crafted input to the plugin’s forms or endpoints; it may require authenticated access to submit parameters, but the description does not state otherwise. Given the nature of the flaw, exploitation could result in full compromise of the underlying database.
OpenCVE Enrichment