Impact
The vulnerability is an SQL Injection flaw caused by improper neutralization of special elements in the Vitepos Lite WordPress plugin, allowing an attacker to inject SQL commands into database queries. This can enable an attacker to read sensitive data, and in some cases modify or delete records, leading to significant confidentiality and integrity compromise. The weakness is identified as CWE-89 and is considered a blind injection, implying that attackers may not see immediate response outputs but can infer the database structure and contents through query results or timing differences.
Affected Systems
The flaw exists in Appsbd Vitepos Lite versions up to 3.6.1. Any WordPress instance that has the Vitepos Lite plugin installed within that version range is vulnerable. All releases from the initial release (“n/a”) through 3.6.1 are affected.
Risk and Exploitability
The CVSS score of 7.6 places this issue in the high severity category. No EPSS score is publicly available, so the current exploitation probability cannot be quantified, but the lack of KEV listing suggests no widespread public exploitation at this time. The likely attack surface is via HTTP requests to the plugin’s endpoints that accept user-supplied parameters without proper sanitization. An attacker with network access to the WordPress site can craft malicious requests to the vulnerable API or form submission and trigger blind SQL queries that return or manipulate data. If the WordPress installation allows anonymous or unauthenticated access to the Vitepos endpoints, the attack requires no privilege escalation. However, even with limited access, the ability to extract or alter data can have severe operational impacts.
OpenCVE Enrichment