Impact
Based on the updated description, the vulnerability is an unauthenticated SQL injection flaw in the DiviNext Woo Essential plugin. User‑supplied input through plugin parameters is not properly escaped, enabling attackers to inject arbitrary SQL statements into backend queries. Attackers could read, modify, or delete data from the WordPress database, including customers, orders, and sensitive login information.
Affected Systems
The vulnerability affects the DiviNext Woo Essential plugin for WordPress up to version 4.3.0. Any WordPress site that has this plugin installed and has not upgraded to a later release is at risk. No specific operating system or PHP version restrictions are noted; attackers only require network access to the site.
Risk and Exploitability
The CVSS score of 9.3 marks it as critical. Because the vulnerability is unauthenticated and can be leveraged through a web request, an attacker only needs to reach the plugin endpoint, making exploitation relatively simple if the plugin is still in use. The EPSS score of 0.00236 (0.236%) indicates a very low probability of exploitation in the wild, yet the low EPSS does not mitigate the high CVSS; the vulnerability is not listed in CISA’s KEV catalog, but its critical score and unauthenticated nature make it a pressing risk for all affected installations.
OpenCVE Enrichment