Impact
The SAMO Forms WordPress plugin through version 1.0.0 fails to properly sanitize and escape user input before incorporating it into SQL queries in several actions that do not require authentication. The flaw is a CWE-89 SQL injection, permitting attackers to inject arbitrary SQL statements, enabling them to read sensitive data, alter stored information, or delete database records. The vulnerability does not grant code execution, but the impact on confidentiality, integrity, and availability of the database is significant.
Affected Systems
All WordPress sites that have the SAMO Forms plugin installed at version 1.0.0 or earlier are affected.
Risk and Exploitability
The flaw can be exploited remotely with no authentication, and the associated CVSS score of 8.6 indicates a high damage potential. Although the EPSS score is less than 1%, the absence of authentication requirements and the high impact classifies the risk as high. The vulnerability is not present in the CISA KEV catalog; however,.
OpenCVE Enrichment