Impact
The vulnerability is an unauthenticated SQL Injection in the Everest Backup plugin for WordPress. An attacker can inject malicious input into SQL statements that are not properly sanitised, enabling arbitrary read, write, or delete operations on the database. This directly compromises the confidentiality and integrity of the website data and can allow further exploitation of the host if database credentials are accessed.
Affected Systems
Versions of the Everest Backup plugin up to and including 2.3.12 are vulnerable; any site that has installed these or earlier releases is at risk.
Risk and Exploitability
The CVSS score of 9.3 signals a critical severity. Because the flaw is unauthenticated, an attacker does not need credentials and can exploit the injection from any external HTTP request that includes malicious parameters. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential for widespread exploitation, as unauthenticated web‑based attacks are broadly available. The likely attack vector is through any publicly accessible endpoint of the plugin that accepts user input.
OpenCVE Enrichment