Impact
The vulnerability is an SQL Injection that allows attackers to carry out blind SQL injection in the Saleswonder LLC WebinarIgnition plugin for WordPress. Through improper neutralization of special characters in user input, an attacker can inject malicious SQL that may allow them to read, modify, or delete data in the database. Depending on privileges, compromised data could lead to broad system compromise. The weakness is catalogued as CWE-89.
Affected Systems
Saleswonder LLC WebinarIgnition plugin for WordPress, affected from any available release up to 4.08.253. No additional platform information is specified.
Risk and Exploitability
The CVSS score is 9.3, indicating a critical severity. The EPSS score is not available, so exploitation probability is unknown, but the lack of listing in CISA KEV suggests that it has not yet been exploited in the wild. Attackers may target the plugin via crafted requests to the WordPress site. The vulnerability is exploitable from external networks, given that it is a plugin exposed through the web interface.
OpenCVE Enrichment