Impact
Administrator-level SQL injection in Leyka versions up to 3.32.3 allows an attacker to inject arbitrary SQL statements. This flaw can lead to reading, modifying, or deleting data stored in the WordPress database, thereby compromising confidentiality, integrity, and potentially availability of the site.
Affected Systems
The vulnerability affects the Leyka fundraising plugin released by Vault Dweller for WordPress, specifically versions 3.32.3 and earlier. No additional affected product versions are listed.
Risk and Exploitability
The CVSS score of 7.6 indicates a high risk level, but no EPSS data is available to gauge current exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation requires that an attacker possess or compromise an administrator account, which then enables the injection of malicious SQL through the plugin’s administrative interface. The limited scope to administrators reduces the likelihood of a broad attack but still poses a significant threat to sites with weak access controls.
OpenCVE Enrichment