Impact
The CWS SVGicons plugin for WordPress contains a blind SQL injection vulnerability due to improper neutralization of special characters used in an SQL command. The flaw allows an attacker to inject arbitrary SQL code into database queries executed by the plugin, potentially leading to data exfiltration, unauthorized data modification, or data deletion. This weakness is classified as CWE‑89, a high‑severity issue that directly undermines the confidentiality, integrity, and availability of the affected WordPress site's database.
Affected Systems
All WordPress installations that have the CreativeWS CWS SVGicons plugin installed at version 1.5.5 or earlier are vulnerable. The plugin’s public documentation lists no later versions as affected, and no other products are indicated by the CNA. Therefore, any site using this plugin at or below the cited version should be considered at risk.
Risk and Exploitability
The CVSS score of 8.5 signifies a EPSS score of less than 1% indicates a very low probability of exploitation as of the latest data, and the vulnerability is not yet present in the CISA KEV catalog. Because the vulnerability is blind, an attacker would need to send crafted inputs to the plugin’s database queries in order to infer data, but the CVE does not disclose a specific entry point or protocol, so the precise attack vector remains unspecified in public sources.
OpenCVE Enrichment