Impact
The DigitalME eRoom WordPress plugin contains a SQL Injection flaw in its input handling layer, allowing an attacker to inject arbitrary SQL statements. This weakness, classified as CWE‑89, exposes the site’s database, permitting unauthorized viewing, alteration, or deletion of stored data. The potential damage includes compromising confidential user information, altering transactional records, and facilitating further attacks on the site’s infrastructure.
Affected Systems
The plugin versions 1.7.1 and earlier are affected. WordPress installations running any of these releases of the eRoom plugin are at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score of less than 1% suggests low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed active exploitation. Likely attack vectors involve an unauthenticated attacker submitting crafted input through the plugin’s public endpoints to manipulate database queries.
OpenCVE Enrichment