Impact
The flaw is a classic SQL injection caused by improper neutralization of special elements used in SQL commands. It allows an attacker to inject blind SQL payloads into the AcyMailing SMTP Newsletter plugin’s input handling, potentially retrieving, modifying, or deleting data stored in the underlying WordPress database.
Affected Systems
All WordPress installations that have the AcyMailing SMTP Newsletter plugin from the AcyMailing Newsletter Team and are running version 10.11.0 or earlier.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is rated critical, but the EPSS score of less than 1 % indicates that real‑world exploitation is rare. The injection is blind, requiring repeated queries or timing attacks to infer results, and the attack vector is through the web layer—any external user that can reach the plugin’s HTTP endpoints can craft the payload.
OpenCVE Enrichment