Impact
The PublishPress Series plugin for WordPress can be exploited by authenticated administrators to inject arbitrary SQL commands. This flaw, classified as CWE-89, enables the attacker to read or modify data stored in the WordPress database, potentially exposing sensitive content or corrupting it.
Affected Systems
The vulnerability is present in all installations of the PublishPress Series plugin with a version of 3.1.3 or earlier. No other WordPress core or plugin versions are mentioned as affected.
Risk and Exploitability
The CVSS base score of 7.6 reflects a medium‑to‑high severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability has not been reported in the CISA KEV catalog, indicating no confirmed active exploitation. Attackers need an authenticated administrator account and knowledge of the plugin’s database structure to conduct the injection, which could lead to unauthorized data access or modification.
OpenCVE Enrichment