Impact
Contributor input in WP Post Author versions up to 3.9.1 is not properly sanitized, allowing a malicious user to inject arbitrary SQL statements. The resulting injection could let an attacker read or modify sensitive database contents, impacting confidential data and potentially allowing full database compromise. The weakness is identified as CWE‑89 and carries a CVSS score of 8.5.
Affected Systems
The vulnerability affects WordPress sites that use the AF Themes WP Post Author plugin version 3.9.1 or earlier. No additional vendor or product information is listed beyond the plugin itself.
Risk and Exploitability
The high CVSS score indicates that the flaw is severe. The EPSS score is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector is through contributor‑level access to post editing pages, where unfiltered data is fed directly to SQL queries without sufficient escaping.
OpenCVE Enrichment