Impact
The John‑Michael L'Allier Create plugin contains a flaw in which unsanitized input is incorporated into SQL commands, leading to a blind SQL injection vulnerability. An attacker who can provide input to the plugin—such as through a contributor interface—can trigger arbitrary SQL statements against the WordPress database. This can result in the unauthorized reading, modification, or deletion of data, threatening the confidentiality and integrity of the site's content.
Affected Systems
WordPress installations that have the John‑Michael L'Allier Create plugin at version 2.5.3 or earlier are affected. Sites running any older revision of the plugin are also vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests that exploitation attempts are currently rare. The flaw is not recorded in the CISA KEV catalog. Given the nature of SQL injection vulnerabilities, the likely attack vector could involve unsanitized inputs in the plugin’s contributor interface within the WordPress admin area.
OpenCVE Enrichment