Impact
The vulnerability is an SQL injection flaw that can be exercised by any site administrator. It allows the injection of arbitrary SQL statements, enabling an attacker to read, alter, or delete data across the WordPress database. The gain of privileges leads to full compromise of site integrity and confidentiality.
Affected Systems
WP Ultimate CSV Importer plugin versions 9.2 and earlier, distributed by Smackcoders Inc., are affected. The plugin must be installed on WordPress sites.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the KEV status shows it is not listed as a known exploited vulnerability. The attack requires administrator access to the WordPress backend and exposure of plugin endpoints, making it likely that only sites with exposed admin interfaces or known credentials are at risk.
OpenCVE Enrichment