Impact
The vulnerability is a classic SQL injection flaw (CWE-89) in the WordPress FluentCRM Pro plugin version 3.1.12 and earlier. Unvalidated input reaches the database layer, allowing an attacker to inject malicious SQL statements. This can result in unauthorized data retrieval, modification, or deletion, potentially granting full control over the WordPress site's database.
Affected Systems
The flaw affects the FluentCRM Pro plugin developed by WP ManageNinja LLC. All installations running version 3.1.12 or older are vulnerable. WordPress sites that rely on the plugin for customer relationship management without applying the patch remain at risk.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. This flaw is a classic SQL injection (CWE-89). The EPSS score is not available, so exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA's KEV catalog. A likely attack vector is via the plugin's publicly exposed interfaces; if a site is accessible over the internet, an attacker can send crafted requests to trigger the injection. The impact could lead to loss of confidentiality or integrity for site data.
OpenCVE Enrichment