Impact
The SEO Booster WordPress plugin contains a generic SQL injection flaw that is triggered by the unsanitized 'sort_field' parameter. Because the plugin fails to escape user input and does not use prepared statements, an attacker who has administrator-level credentials can append malicious SQL to the existing query. This practice lets the attacker read or potentially alter any data stored in the database and is exemplified by CWE‑89.
Affected Systems
All installations of the SEO Booster plugin from cleverplugins that are version 7.3.1 or older are impacted. This includes any WordPress site that has not upgraded beyond the 7.3.1 release. Administrators or users with higher privileges on those sites possess the required access to exploit the flaw.
Risk and Exploitability
The CVSS score of 4.9 indicates a low‑to‑moderate severity, but the vulnerability is meaningful because exploitation requires authenticated administrator access. The EPSS score of less than 1% shows that exploitation is unlikely, yet it remains a risk if administrator credentials are compromised. The vulnerability is not listed in CISA’s KEV catalog, which suggests that there have been no known large‑scale attacks yet, but the potential for confidential data loss exists.
OpenCVE Enrichment