Impact
The vulnerability is an unauthenticated SQL injection in the RealPress plugin, affecting versions up to and including 1.1.2. An attacker can inject arbitrary SQL, potentially retrieving or modifying sensitive data and compromising the WordPress site.
Affected Systems
The vulnerability impacts the ThimPress RealPress plugin version 1.1.2 and earlier. WordPress sites that have installed any of those versions are exposed.
Risk and Exploitability
With a CVSS score of 9.3, this flaw represents a highly severe risk. The exact likelihood of exploitation is unknown as EPSS data is not available, and it is not currently listed in CISA’s KEV catalog, suggesting no widely known exploits yet. Nonetheless, the lack of authentication requirements and the plugin’s handling of user input indicate that an attacker could exploit this remotely by sending crafted requests to the vulnerable plugin, potentially leading to data theft, corruption, or further compromise of the host.
OpenCVE Enrichment