Impact
The vulnerability is a SQL injection flaw that allows an attacker to inject arbitrary SQL statements through the contributor input fields of the WP EasyCart plugin. This can enable unauthorized access to or modification of data stored in the plugin’s database, potentially compromising confidentiality and integrity.
Affected Systems
Levelfourdevelopment’s WordPress WP EasyCart plugin versions up to and including 5.9.0 are affected. Versions newer than 5.9.0 are not reported as vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score of less than 1% points to a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the web interface via contributor data submissions that are not properly sanitized.
OpenCVE Enrichment