Impact
This vulnerability is an unauthenticated SQL injection flaw in the WordPress Quotes llama plugin versions up to 3.1.5. An attacker can inject arbitrary SQL payloads into the plugin’s database queries, allowing them, modify content, delete records, or in some configurations execute further malicious code. The impact encompasses loss of confidentiality, integrity, and potentially availability of the website’s data.
Affected Systems
The flaw affects the Quotes llama plugin developed by oooorgle, used on WordPress sites. All installations of the plugin with a version of 3.1.5 or earlier are impacted.
Risk and Exploitability
With a CVSS score of 9.3, this issue is critically severe. The EPSS score is not available, but the lack of authentication requirement and the widespread use of WordPress point to a high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the ability to access the site’s database unauthenticated provides a clear attacker path.
OpenCVE Enrichment