Impact
The vulnerable Link Library WordPress plugin (pre‑7.9.3) fails to sanitise user input submitted through its front‑end link submission form. This flaw allows unauthenticated attackers to inject malicious SQL statements that execute with the database user’s privileges, potentially permitting arbitrary data extraction, modification, or loss of integrity.
Affected Systems
WordPress sites using the Link Library plugin before version 7.9.3 are affected. The vulnerability exists in the front‑end submission form; any site hosting the plugin without an updated version is at risk.
Risk and Exploitability
The CVSS score is 9.1, but the flaw permits unauthenticated exploitation via the public web interface, enabling attackers to compromise the database. EPSS score < 1% and the vulnerability is not listed in CISA KEV, however the lack of authentication and the ability to alter data represent a high risk for confidentiality and integrity.
OpenCVE Enrichment