Impact
A SQL injection flaw exists in versions of the WordPress Persistent Login plugin up to 3.1.0, allowing an attacker to inject arbitrary SQL statements through the subscriber interface. This could enable the exfiltration of sensitive data, modification or deletion of user credentials, and may provide a foothold for further exploitation depending on the database configuration and web application context.
Affected Systems
The vulnerability affects the WordPress Persistent Login plugin by lukeseager. All releases dated 3.1.0 or earlier are impacted; any installation of this plugin version requires immediate attention.
Risk and Exploitability
The CVSS score of 8.5 classifies this issue as high severity. The EPSS score is not available, making it difficult to gauge current exploitation prevalence. It is not listed in CISA’s KEV catalog. The likely attack vector is remote, via crafted HTTP requests to the plugin’s subscriber endpoint; an attacker does not need authentication to send the payload.
OpenCVE Enrichment