Impact
Unauthenticated SQL Injection exists in the WordPress WPDM – Premium Packages plugin in all releases up to and including version 6.2.0. The flaw allows an attacker to inject arbitrary SQL statements into database queries without any user authentication. If exploited, an attacker could read, modify, or delete sensitive data stored in the WordPress database, potentially compromising site confidentiality and integrity.
Affected Systems
The vulnerability affects installations of the Shahjada WPDM – Premium Packages plugin for WordPress, specifically any instance running version 6.2.0 or earlier. Users should verify that they are running at least version 7.0.0, which contains the fix, or remove the plugin entirely if upgrade is not feasible.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity, and while the EPSS score is below 1%, indicating a low probability of active exploitation at the time of analysis, the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by crafting malicious HTTP requests that target the plugin’s input handling, bypassing any need for authentication.
OpenCVE Enrichment