Impact
Media Sweep – WordPress Media Cleaner contains a flaw that permits generic SQL injection through the 'fields' parameter. In all releases up to and including 1.1.3, unescaped user input is concatenated directly into SQL statements, and no prepared statements are used. This defect provides an authenticated attacker with administrator or higher privileges the ability to append additional SQL queries to existing queries, thereby extracting confidential data from the database.
Affected Systems
WordPress sites that run Media Sweep version 1.1.3 or earlier are affected. The vulnerability exists in WPcreatix’s Media Sweep – WordPress Media Cleaner plugin across all impacted versions. Any site using a plugin instance that supplies a "fields" parameter to the REST API endpoints or internal scans is susceptible.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate overall risk, and the EPSS score is not reported, so current exploitation probability is unknown. The plugin’s attack requires an authenticated user with administrative-level access to the WordPress installation, implying an internal or privileged threat model. The vulnerability is not listed in CISA’s KEV catalog, but if an attacker gains admin access, they could run arbitrary SQL read operations. Given the lack of a public exploit, the risk remains moderate, and the recommended response is to patch as soon as possible.
OpenCVE Enrichment