Impact
An attacker can exploit a blind SQL Injection flaw in the Neoforum WordPress plugin caused by improper neutralization of special characters in database queries. This allows the injection of arbitrary SQL statements through crafted input, potentially revealing, modifying, or deleting sensitive data stored in the WordPress database. The impact is a breach of confidentiality, integrity, and possibly availability of the site’s content and user information.
Affected Systems
Any WordPress installation that incorporates the Neoforum plugin version 1.0 or earlier, distributed by saeros1984. The vulnerability exists in all releases up to and including 1.0, with no earlier version information available.
Risk and Exploitability
The flaw is rated with a CVSS score of 7.6, indicating high severity. The EPSS score of less than 1% suggests that, as of current data, exploit attempts are rare, and the vulnerability is not currently part of the CISA KEV catalog. The likely attack vector is via web requests directed at the plugin’s input points; authentication is not explicitly required, but the details are not fully disclosed in the description. An attacker can leverage the blind nature of the injection to infer database structure and extract information without immediate error messages.
OpenCVE Enrichment