Impact
The vulnerability is a classic SQL injection that allows a malicious actor to manipulate SQL queries executed by the WordPress Uncanny Automator plugin. Because it can alter database operations, an attacker could read, modify, or delete sensitive data. The weakness is classified as CWE-89.
Affected Systems
The issue affects the Uncanny Owl Uncanny Automator plugin for WordPress versions up to and including 7.3.2. Any WordPress site that has installed one of these versions is susceptible.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of immediate exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack requires administrator privileges, meaning the actor must be authenticated as a site admin or otherwise gain the ability to inject malicious code into the plugin’s database operations. Exploitation would involve sending specially crafted requests that exploit unsanitized input handling within the plugin’s code.
OpenCVE Enrichment