Impact
A vulnerability in YOOtheme Pro allows authenticated contributor users to perform SQL injection against the Joomla site's database. The flaw lets an attacker inject or modify SQL statements controlling content creation, enabling the execution of arbitrary queries that could alter, delete, or exfiltrate data. The weakness is a classic input validation flaw classified as CWE-89.
Affected Systems
All installations of YOOtheme Pro for Joomla using versions 1.0.0 through 5.0.40 are affected. The product is distributed by yootheme.com.
Risk and Exploitability
The CVSS score of 8.6 categorizes this issue as high. The EPSS score is <1% (0.0026), indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited by any user with contributor privileges, making it highly actionable for attackers who have legitimate access to the site. The likely attack vector is an authenticated contribution workflow that fails to sanitize input parameters.
OpenCVE Enrichment