Impact
The vulnerability in the WordPress ProLancer Element plugin allows an attacker to perform a SQL injection via the subscriber feature. In versions 1.4.8 or earlier, user‑submitted data is incorporated into database queries without adequate sanitization. Based on the description, this could enable an attacker to execute arbitrary SQL statements against the site’s database, potentially exposing, altering, or deleting sensitive information.
Affected Systems
WordPress sites that have the ThemeBing ProLancer Element plugin installed in version 1.4.8 or earlier are affected. No additional vendor or version details are provided beyond the ≤1.4.8 boundary.
Risk and Exploitability
The CVSS score of 8.5 indicates a High severity, suggesting significant risk if exploited. EPSS data is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the subscriber interface exposed by the plugin, where malicious input may be injected into SQL statements.
OpenCVE Enrichment