Impact
The Comments WordPress plugin before version 7.6.66 does not validate a parameter used to build a database query, allowing an attacker to inject arbitrary SQL. The injected text is treated as SQL grammar rather than data, so it cannot extract arbitrary database contents, but it can expose comments that the attacker is not entitled to see, including those awaiting moderation, marked spam, trashed, or posted to private or draft entries. The resulting confidentiality impact is limited to the content of those comments.
Affected Systems
The vulnerability affects the Comments WordPress plugin (generic name "Comments", vendor unknown) on all installations running a version earlier than 7.6.66.
Risk and Exploitability
The attacker can read private or pending comments via an unauthenticated request, but cannot modify data or obtain arbitrary database content. The vulnerability, with a CVSS score of 5.3, poses a moderate information disclosure risk and is exploitable by any web user. Since the vulnerability is not yet cataloged by CISA, expected exploitation rates are uncertain, but the ease of attack warrants prompt attention.
OpenCVE Enrichment