Impact
A subscriber endpoint in the eShipper Commerce WordPress plugin has a flaw that allows execution of arbitrary SQL commands because input is not fully validated. The vulnerability can lead to reading, modifying, or deleting database records, potentially exposing sensitive information or elevating privileges on the affected site. The weakness is mapped to CWE‑89.
Affected Systems
WordPress sites that use the eShipper Commerce plugin version 2.16.13 or earlier are impacted. This plugin is distributed by WordPress.com.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. EPSS is not available and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the subscriber endpoint can be accessed without authentication, allowing attackers to send crafted requests that trigger the SQL injection from the public internet. This makes exploitation straightforward for anyone who can reach the endpoint.
OpenCVE Enrichment