Impact
The Smart Marketing SMS and Newsletters Forms plugin for WordPress contains a classic SQL Injection flaw (CWE-89) that allows authenticated users with subscriber-level or higher privileges to craft specially named parameters that inject additional SQL statements into existing database queries. This unescaped injection can be used to extract arbitrary data from the site's database, leading to confidential data exposure.
Affected Systems
All releases of the egoi Smart Marketing SMS and Newsletters Forms plugin with a version number of 5.1.24 or lower are impacted. The flaw is active only when the['enabled'] is true) and the get_option('egoi_mapping') value is truthy,.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker would need authenticated access with at least subscriber-level privileges and the sync feature enabled to inject and execute additional SQL queries, making the practical risk limited by the specific configuration and authentication requirements.
OpenCVE Enrichment