Impact
The plugin contains an unauthenticated SQL injection flaw that allows an attacker to inject arbitrary SQL statements into backend queries. This could enable an attacker to read, modify, or delete database content associated with the site. The primary impact is breach of data confidentiality, integrity or availability, as appropriate for the data stored in the database. The flaw is classified as CWE‑89. All statements about potential data modification or loss are inferred from the nature of the vulnerability and not explicitly stated in the CVE description.
Affected Systems
The affected software is the WordPress File Upload plugin by nickboss, version 5.1.7 and older. Users of any of these versions are vulnerable unless the plugin is updated or disabled.
Risk and Exploitability
The vulnerability is unauthenticated and can be accessed through the standard file‑upload interface of the plugin. The CVSS score of 9.3 denotes critical severity, indicating a high potential impact if exploited. The EPSS score is not available, so the current probability of exploitation is unknown. The vendor has not listed this issue in the CISA KEV catalog, but the absence of KEV listing does not mitigate the risk posed by the high severity score.
OpenCVE Enrichment