Impact
The vulnerability in the WordPress Community by PeepSo plugin up to version 9.0.5.2 allows an attacker to inject arbitrary SQL statements through subscriber inputs. The flaw can lead to unauthorized reading or modification of database records, potentially exposing sensitive user data, altering membership privileges, and disrupting site functionality.
Affected Systems
The issue affects installations of the PeepSo:Community by PeepSo plugin on WordPress that are using any release up to 9.0.5.2. The affected component is the plugin code that constructs SQL queries without proper sanitization for subscriber inputs.
Risk and Exploitability
The predicted impact is high, reflected by a CVSS score of 8.5. The EPSS score of 0.00278 indicates a very low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface, taking advantage of publicly accessible subscriber input fields. If an attacker successfully abuses the flaw, they could achieve data exfiltration or database alteration.
OpenCVE Enrichment