Impact
The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress contains a time‑based blind SQL injection flaw in the 'orderby' parameter. Because the plugin does not properly escape this parameter or use prepared statements, an authenticated administrator or higher can inject arbitrary SQL into the existing query. This allows the attacker to retrieve sensitive data such as user credentials, subscription lists, or other database content, thereby compromising the confidentiality of the site's data.
Affected Systems
All installations of the EnvíaloSimple: Email Marketing y Newsletters WordPress plugin from version 1.x through 2.4.5 are affected. The plugin is maintained by the vendor dattateccom. Users running any of these versions on a WordPress site are vulnerable until an update that removes the flaw is applied.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity. The vulnerability requires authenticated access with administrator privileges, so it is not exploitable by an unauthenticated attacker. EPSS is not available and the issue is not listed in CISA's KEV catalog, suggesting no widespread exploitation is currently known. However, because the flaw allows the extraction of arbitrary data, a compromised administrator account can cause data loss or exposure. Attackers would need to repeatedly trigger the time‑based delay to infer query results, making the attack tedious but feasible for persistent adversaries.
OpenCVE Enrichment