Impact
The iNET Webkit 1.2.4 WordPress plugin contains an unsanitized input field in its contributor feature, leading to a classic SQL injection flaw (CWE‑89). The description does not enumerate the exact damage, but it is inferred that a successful exploit would allow an attacker to read, alter, or delete data held in the WordPress database, thereby compromising site integrity.
Affected Systems
WordPress installations that have the iNET Webkit plugin version 1.2.4 deployed are affected; the flaw is confined to the contributor component of the plugin, so sites that do not enable or use this feature are not impacted.
Risk and Exploitability
The vulnerability is scored 8.5 on CVSS, indicating high severity, and its EPSS score is less than 1%, showing that exploitation events have been rare to date. It is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request sent to the contributor endpoint, where attacker‑supplied input is incorporated into SQL statements without proper sanitization. If exploited, the attacker could gain read or write access to the WordPress database, potentially compromising all content and site integrity.
OpenCVE Enrichment