Impact
An unauthenticated SQL Injection vulnerability exists in the Boost plugin for WordPress versions 2.0.4 and earlier. The flaw allows an attacker to embed arbitrary SQL statements within plugin requests, which are executed by the database without requiring authentication. An exploitation can lead to unauthorized read, modification, or deletion of database contents, directly compromising data confidentiality and integrity.
Affected Systems
WordPress sites that have the PixelYourSite Professional:Boost plugin version 2.0.4 or earlier installed are affected. Any user or attacker who can reach the plugin's endpoints can exploit the flaw, regardless of administrative credentials.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. Because the EPSS score is not available, the probability of exploitation is unknown, but the lack of authentication requirements and the plugin’s wide distribution make the vulnerability attractive to attackers. The vulnerability is not listed in the CISA KEV catalog. The typical attack path is remote via HTTP(S) to the plugin’s request endpoint, as inferred from its nature.
OpenCVE Enrichment