Impact
The vulnerability exists in the WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress and allows an attacker with author-level access or higher to inject arbitrary SQL through the wpma_metabox_authors_list parameter. Because the parameter is not properly escaped and the existing query is not prepared, the attacker can append additional SQL statements. The impact of exploiting this flaw is the extraction of sensitive information from the underlying database, which compromises confidentiality of stored data. The weakness is identified as a classic input validation flaw (CWE‑89).
Affected Systems
aThemes’ WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin is affected in all versions up to and including 3.9.1. Users running any of these versions must determine their install's version and confirm whether it is vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is authenticated; an attacker must possess an author role or higher to inject the payload, and the exploitation requires that an administrator subsequently loads the post list screen to trigger the injection. As the vulnerability entails sensitive data disclosure, the risk to an organization with exposed WordPress installations is significant, especially if author permissions are broadly granted.
OpenCVE Enrichment