Impact
The vulnerability is an Improper Neutralization of Special Elements used in an SQL Command, commonly referred to as a SQL Injection flaw. It allows an attacker to conduct blind SQL injection against the WordPress Kir or manipulation of data stored in the database without revealing an error message. The exploitation of this flaw could lead to unauthorized disclosure of sensitive information or modification of database contents, thereby compromising confidentiality and integrity of the website data.
Affected Systems
WordPress installations using the Themeum Kirki plugin version 6.0.12 or earlier are affected. All prior versions through 6.0.12 are vulnerable, version is at risk.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical vulnerability. Although the EPSS score is less than 1 percent, indicating a low documented exploitation probability, the lack of a KEV listing does not negate the need for remediation. Based on the description, it is inferred that an attacker would likely target exposed plugin endpoints that accept user input, leveraging the blind nature of the injection to infer backend data through timing or boolean responses. Given the severity, the risk to affected organizations warrants immediate action.
OpenCVE Enrichment