Impact
The vulnerability is an unauthenticated SQL injection in the Qode Tours WordPress plugin. It allows an attacker to inject arbitrary SQL queries, potentially compromising database confidentiality and integrity. This flaw is a classic injection (CWE‑89) that may lead to data theft, modification, or loss.
Affected Systems
WordPress sites that use the Qode Tours plugin version 3.1.3.1 or earlier. The affected product is the Qode Tours plugin by QODE, which is integrated into the WordPress CMS.
Risk and Exploitability
With a CVSS score of 9.3, the vulnerability presents a high risk and is exploitable from any network location without authentication. The EPSS score is not provided, but the lack of an official KEV listing suggests no known public exploits yet. However, because the attack vector is unauthenticated and relies on crafted requests to the plugin, an attacker can easily test and abuse the flaw to gain unauthorized database access.
OpenCVE Enrichment