Impact
The vulnerability is an improper neutralization of special elements in an SQL command, known as SQL injection, in the WordPress Collapsing Categories plugin. Attackers can send crafted input that is incorporated directly into an SQL query, allowing them to execute arbitrary database queries. The effect can grant an attacker read or modify access to WordPress database content, potentially exposing sensitive data or altering site functionality.
Affected Systems
The flaw affects all installations of the robfelty Collapsing Categories plugin with a version number from the initial release up to and including 3.0.9. No specific version ranges beyond 3.0.9 are impacted, and versions newer than 3.0.9 are presumed unaffected.
Risk and Exploitability
The CVSS score is 8.5, indicating high severity. The EPSS score is less than 1%, suggesting a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a blind SQL injection, requiring the attacker to submit crafted requests to the vulnerable plugin endpoints to infer database structure or extract data.
OpenCVE Enrichment