Impact
Unauthenticated SQL Injection in the Beautiful Taxonomy Filters WordPress plugin permits attackers to inject arbitrary SQL statements into database queries. The flaw is present in all plugin releases up to and including version 2.4.6 and is triggered by publicly accessible plugin parameters. If exploited, an attacker could read, alter, or delete site data, compromise user accounts, or use the site as a foothold for further attacks. This is a severe, high‑risk weakness (CWE‑89) impacting confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
WordPress sites using the Beautiful Taxonomy Filters plugin from Jonathan de Jong, versions 2.4.6 and earlier. Upgrading to the latest release (2.4.7 or newer) removes the vulnerability.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. With no EPSS score available yet and the vulnerability being unauthenticated, any visitor to the site can construct a malicious request to trigger the flaw. Attackers can readily use automated scanners to locate the vulnerable endpoint and inject custom SQL, potentially leading to data exposure or site compromise. Although a KEV listing is absent, the public nature and high severity warrant immediate mitigation.
OpenCVE Enrichment