Impact
The John‑Michael L'Allier Create plugin includes a flaw that allows contributors to inject arbitrary SQL statements. By supplying unsanitized input, an attacker can read, change, or delete data stored in the WordPress database, compromising the confidentiality and integrity of site information.
Affected Systems
WordPress installations that have the John‑Michael L'Allier Create plugin at version 2.5.3 or earlier are affected. Sites running any older revision of the plugin are also vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests that exploitation attempts are currently rare. The flaw is not recorded in the CISA KEV catalog. Given the nature of SQL injection vulnerabilities, the likely attack vector could involve unsanitized inputs in the plugin’s contributor interface within the WordPress admin area.
OpenCVE Enrichment