Impact
The affiliate‑toolkit plugin contains a blind SQL injection flaw that allows an attacker to send specially crafted input that is concatenated into database queries. This weakness can be exploited to read or extract arbitrary data from the shop or content database, potentially revealing sensitive user information or credentials. The vulnerability exists in all releases up to and including version 3.9.1 and is listed as a CWEs for the specific weakness of SQL injection.
Affected Systems
The flaw is present in SERVIT Software Solutions affiliate‑toolkit plugin, version 3.9.1 and earlier. Users running this plugin on a WordPress installation are at risk, regardless of the host server configuration or the plugin’s usage scope within the site.
Risk and Exploitability
The CVSS score of 7.6 classifies the issue as high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack surface is via web requests targeting the plugin’s parameters, and because the injection is blind, an attacker would need to probe the response to infer successful exploitation. If successful, the attacker could gain read access to the database and thereby compromise data confidentiality.
OpenCVE Enrichment