Impact
The vulnerability is an unauthenticated SQL injection flaw present in WordPress/Listdom plugin versions 5.6.0 and older. Through improperly sanitized user input, an attacker can inject arbitrary SQL statements that are executed by the underlying database. This weakness can compromise database confidentiality and integrity and may provide a foothold for further exploitation such as remote code execution or privilege escalation. The flaw is characterized by CWE‑89.
Affected Systems
The affected component is the Webilia Inc. Listdom plugin for WordPress. Any site running Listdom 5.6.0 or earlier is vulnerable. No specific WordPress core versions are mentioned; the plugin alone is required to be updated. Version 5.7.0 or later contains the fix.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity, and the lack of an EPSS score means the current exploitation probability is not quantified, but the vulnerability is not known to be exploited in the wild (not listed in KEV). Attackers can leverage the vulnerability from any user without authentication, which means the attack vector is remote and straightforward. In practice, an attacker can gain full control over the affected database.
OpenCVE Enrichment