Impact
The WP‑Lister Lite for eBay WordPress plugin is vulnerable to generic SQL Injection through the 'orderby' parameter in all releases up to and including 3.8.8. The vulnerability arises because user‑supplied values are not properly escaped and the plugin fails to prepare the SQL query. As a result, authenticated users with shop manager‑level access or higher can inject additional SQL commands and concatenate them to the existing query, allowing the extraction of sensitive data from the database. This flaw corresponds to CWE‑89.
Affected Systems
All releases of WP‑Lister Lite for eBay up to and including version 3.8.8, distributed by wp‑lab. The plugin integrates with WordPress sites that use the eBay synchronization features.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires authenticated shop manager or higher privileges, the exposure is limited to sites with such accounts. A successful exploit would grant the attacker read access to the site’s database content, potentially leading to data leakage.
OpenCVE Enrichment