Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, allowing a blind SQL injection into the Sirv WordPress plugin. An attacker who can supply input that reaches the plugin's SQL queries can read or modify database contents, potentially compromising the confidentiality and integrity of sensitive data stored by the site.
Affected Systems
WordPress sites using the Sirv plugin, with affected plugin versions 8.2.5 and prior. The vendor is Sirv and the product is the Sirv WordPress plugin.
Risk and Exploitability
The CVSS base score of 8.5 indicates high severity, and the EPSS score is currently unavailable, meaning the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, starting from a web request to the WordPress site that can manipulate the plugin’s SQL queries.
OpenCVE Enrichment