Impact
Unauthenticated SQL Injection exists in the WordPress Epayco plugin up to version 8.4.6, allowing an attacker to craft arbitrary SQL statements. The flaw can compromise data confidentiality, integrity, and availability by modifying or extracting sensitive database contents. This category of vulnerability falls under CWE-89.
Affected Systems
The issue affects the ePayco WordPress plugin supplied by the ePayco vendor, specifically all releases through 8.4.6. Systems running WordPress and any site that has installed the Epayco plugin without updating beyond 8.4.6 are at risk.
Risk and Exploitability
With a CVSS score of 9.3, this vulnerability is considered critical. No EPSS data is available. Based on the description, the flaw is unauthenticated, allowing any actor to send malicious queries. The exact entry point is not specified in the provided data; it is likely an exposed plugin endpoint. The vulnerability is not listed in the CISA KEV catalog, yet its high severity and ease of exploitation present a significant threat.
OpenCVE Enrichment