Impact
An administrator-level SQL Injection flaw exists in WordPress WPMasterToolKit plugin versions 2.22.0 and earlier. The vulnerability permits an authenticated attacker with plugin administrative rights to inject arbitrary SQL statements, potentially exposing or modifying sensitive database contents and compromising data confidentiality and integrity.
Affected Systems
The affected product is Ludwig You:WPMasterToolKit for WordPress. Any deployment using plugin version 2.22.0 or older is vulnerable.
Risk and Exploitability
The CVSS score of 7.6 classifies the issue as High severity, while the EPSS score is not available, indicating uncertainty about current exploitation rates. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires administrative access to the plugin through the WordPress dashboard; attackers may therefore need credentials or exploit a separate configuration weakness to gain that access.
OpenCVE Enrichment