Impact
The Code Snippets WordPress plugin prior to version 3.10.0 contains a SQL injection flaw in its snippet‑migration import endpoints. Unsanitised user input is directly interpolated into a SQL query, allowing authenticated site administrators to craft UNION-based injections that reach shared network tables. This flaw is not accidental; it is a classic injection weakness that leads to the disclosure of sensitive data, such as other users' password hashes, across a multisite network.
Affected Systems
The vulnerability affects the Code Snippets plugin for WordPress versions earlier than 3.10.0. In a multisite deployment, any subsite administrator who is not a network super administrator can exploit the flaw, because subsite administrators have permission to access the migration importer endpoints.
Risk and Exploitability
The issue is not listed in the CISA KEV catalog, and EPSS data is not available, but the inherent capability to read network‑wide user credentials creates a high potential impact. An attacker who gains site‑admin privileges can construct a UNION‑based payload, force execution of the query, and retrieve hashed passwords from shared tables. The lack of published exploit code does not diminish the likelihood of exploitation, especially on networks with many subsite administrators. Given the severity of credential exposure, the recommended response is to patch immediately.
OpenCVE Enrichment