Impact
The Visualizer plugin for WordPress does not properly validate contributor input, enabling attackers to craft malicious SQL queries that are executed against the database. This injection flaw can lead to unauthorized data exposure, alteration, or deletion, representing a classic CWE‑89 weakness that compromises the confidentiality and integrity of site data.
Affected Systems
Themeisle’s Visualizer add‑on for WordPress is affected. All releases up to and including version 4.0.6 contain the vulnerability; newer releases are not listed as affected.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity, while the EPSS score of less than 1% suggests a low current probability of exploitation. Because the flaw requires a contributor‑level action, the most likely attack vector involves a compromised contributor account or phishing that elevates an attacker to that role. The vulnerability is not listed in the CISA KEV catalog, implying no widespread known exploitation at this time.
OpenCVE Enrichment