Impact
The vulnerability arises from improper handling of input that can be incorporated into an SQL command, enabling blind SQL injection. An attacker can send crafted requests that cause the plugin to execute unauthorized SQL statements, potentially reading, modifying, or deleting data from the underlying database. The impact is therefore a compromise of data confidentiality, integrity, and availability for the affected WordPress site.
Affected Systems
WordPress sites that use the Captivate Sync plugin from captivateaudio’s Captivate Sync, specifically any deployment using versions up to and including 3.3.2. No other vendors or products are explicitly affected.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity with a significant risk of exploitation. The EPSS score is not available, so the exact exploitation likelihood is uncertain, but the vulnerability remains a serious concern. It is not listed in the CISA KEV catalog, yet the blind nature of the SQL injection means attackers could extract data without immediate detection. The likely attack vector is via web requests to the plugin’s endpoints that do not properly sanitize input.
OpenCVE Enrichment