Impact
The SM Page Duplicator WordPress plugin fails to sanitize a stored value before incorporating it into a SQL query used during page duplication. This flaw permits users with the Editor role or higher to inject arbitrary SQL code, potentially allowing them to read, modify, or delete database records. The vulnerability directly compromises database confidentiality and integrity and can be leveraged to tamper with site content or extract sensitive information.
Affected Systems
Any WordPress installation that uses the SM Page Duplicator plugin version 1.0.0 or earlier.
Risk and Exploitability
The risk is heightened for sites where Editor privileges are granted to many users; the vulnerability requires authenticated access but not elevated privileges beyond the role. Because the plugin does not sanitize inputs, the attack is straightforward for a legitimate Editor to perform. The CVSS score of 8.1 indicates high severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the potential for data loss remains significant due to the direct database access offered by the injection.
OpenCVE Enrichment