Impact
The CMS für Motorrad Werkstätten plugin is vulnerable to SQL injection via the ‘arttype’ parameter in all releases up to 1.0.0. The lack of proper escaping and query preparation lets an attacker who has authenticated subscriber‑level or higher privileges append malicious SQL to the existing statement, enabling extraction of sensitive database content. The flaw does not provide code execution but can compromise confidential information.
Affected Systems
WordPress installations using the tholstkabelbwde "CMS für Motorrad Werkstätten" plugin up to and including version 1.0.0 are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires that the attacker is already authenticated as a subscriber or higher; thus the attack vector is likely local application with elevated privileges. Successful exploitation would allow the attacker to read or export data from the WordPress database, posing a confidentiality risk.
OpenCVE Enrichment