Impact
The vulnerability allows an attacker to inject arbitrary SQL statements into the database through unvalidated input fields within the WCFM Marketplace plugin. This flaw can lead to disclosure of sensitive data, modification of database contents, or deletion of critical information, thereby compromising both the confidentiality and integrity of the affected WordPress site.
Affected Systems
All installations of the WC Lovers WCFM Marketplace plugin running versions up to and including 3.8.1 are affected. Sites that have not yet updated beyond this version remain vulnerable.
Risk and Exploitability
The CVSS score of 9.3 marks the issue as critical. The EPSS score is not available, but the vulnerability’s nature – unauthenticated and web‑based – suggests the potential for widespread exploitation. The flaw is not listed in CISA KEV. The likely attack vector is via web requests that contain SQL‑payloads directed at the plugin’s input endpoints. Based on the description, it is inferred that any visitor to the site could attempt to exploit the flaw if they can send crafted requests to the plugin’s actions.
OpenCVE Enrichment