Impact
The affiliate‑toolkit WordPress plugin is vulnerable to time‑based SQL injection through the orderby parameter in all versions up to and including 3.8.8. The flaw stems from insufficient escaping of user input and the lack of proper query preparation. Consequently, an attacker who has authenticated with administrator‑level rights can append malicious SQL statements to the existing query, allowing extraction of sensitive information from the database. This vulnerability is a classic example of CWE‑89, reflecting improper handling of untrusted input in SQL queries.
Affected Systems
The affected product is the cservit affiliate‑toolkit – Multi‑Network Affiliate & Amazon Product Display plugin for WordPress. Versions up to and including 3.8.8 are impacted. Any site running the plugin without upgrading to a safer release is at risk.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the evidence for widespread exploitation is limited at present. However, exploitation requires administrator or higher privileges, so the attack vector is authenticated. An attacker with those credentials can leverage the time‑based injection to retrieve private data from the database. The lack of a publicly disclosed exploit chain limits known malicious activity as of this analysis.
OpenCVE Enrichment