Impact
The Eight Day Week Print Workflow plugin for WordPress contains a time‑based blind SQL Injection vulnerability in the 'title' parameter of the pp-get-articles AJAX action. The flaw arises from insufficient escaping and a lack of prepared statements, allowing an authenticated user with Subscriber or higher privileges to inject SQL code and execute additional queries. This can enable the extraction of sensitive database information, including user data and plugin configuration settings, effectively leading to data theft.
Affected Systems
WordPress installations that have the 10up Eight Day Week Print Workflow plugin installed in any version up to and including 1.2.6 are affected. Both site administrators and content authors with Subscriber‑level access or higher can leverage the vulnerability if the plugin is active.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity risk. Because an attacker must be authenticated and possess at least Subscriber rights, the vector is limited to legitimate users logged into the site; the exploit remains local to the web application. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that public exploitation may be limited but the potential for data compromise is real. Proper preparation and escaping of user input would close this attack path.
OpenCVE Enrichment