Impact
An unauthenticated SQL Injection flaw exists in NGG Smart Image Search plugin versions earlier than 4.0.0. Attackers can inject arbitrary SQL statements through the plugin’s input handling without any form of user authentication, allowing them to read, modify, or delete database contents. The vulnerability falls under CWE‑89, which categorizes flaws in SQL query construction.
Affected Systems
All WordPress sites that have the NGG Smart Image Search plugin installed with a version earlier than 4.0.0 are affected. The vendor product is the wpo‑HR NGG Smart Image Search plugin; specific affected versions are not enumerated beyond the 4.0.0 threshold.
Risk and Exploitability
The CVSS score of 9.3 places this flaw in the Critical severity range. The EPSS score of < 1% indicates a very low, but non‑zero, likelihood of exploitation. It is not listed in CISA’s KEV catalog. Because authentication is not required, the likely attack vector is a remote web request, and the flaw can be exploited by any external user who can send requests to the affected plugin’s endpoints.
OpenCVE Enrichment