Impact
The vulnerability is a classic SQL Injection that can be triggered by unauthenticated users. An attacker can supply crafted input to manipulate the underlying database queries, allowing read or modification of sensitive data stored by the GEO my WordPress plugin. The impact ranges from data exfiltration to altering database contents, which could ultimately enable further exploitation or compromise of website integrity.
Affected Systems
Vendors and products affected include GEO my WordPress by Eyal Fitoussi. All sites running any version of the plugin up to and including 4.5.5 are vulnerable. Users are advised to confirm the plugin version and upgrade to 4.5.5.1 or later.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity and the very low EPSS (< 1%) suggests the likelihood of exploitation in the near term is low, but the vulnerability remains critical. It is not listed in CISA’s KEV catalog. The attack vector is unauthenticated, meaning any external user could exploit it without credentials. If exploited, the attacker could bypass authentication, read or write database content, and potentially hijack the site or exfiltrate sensitive data.
OpenCVE Enrichment