Impact
The Create plugin for WordPress contains an insufficiently escaped 'order_by' parameter that permits generic SQL injection. When presented by an authenticated user with Author-level access or higher, an attacker can inject additional SQL statements into an existing query, allowing the extraction of private data from the database. The vulnerability is caused by the lack of parameterization and inadequate input filtering on this variable.
Affected Systems
The affected product is the Create plugin from mischiefmarmot, with all releases up to and including 2.5.3 susceptible to this flaw. Any WordPress site that has installed this plugin and has authorized users with the 'author' capability (or higher) is at risk.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate impact, but the EPSS score of less than 1% suggests low likelihood of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires authenticated access; the REST endpoint allows authors (through the publish_posts capability) to hit the vulnerable code path without further restrictions, enabling the injection of SQL that can then read sensitive information. The attacker does not gain elevated server privileges; success is limited to database access confined to the WordPress installation.
OpenCVE Enrichment