Impact
An unauthenticated SQL Injection vulnerability exists in Depicter Slider versions 4.8.0 and earlier. Attackers can submit specially crafted SQL statements through the plugin’s input fields, which are then executed against the WordPress database. This allows the attacker to read, modify, or delete data stored in the database. The weakness is classified as CWE-89, indicating a classic injection flaw.
Affected Systems
The Depicter Slider plugin released by averta for WordPress is affected. All releases of version 4.8.0 and earlier are vulnerable. Sites that have installed these versions face this risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in CISA KEV, indicating no publicly documented exploits to date. The attack vector is likely remote via crafted HTTP requests to the plugin’s endpoints, allowing an attacker to inject arbitrary SQL commands.
OpenCVE Enrichment