Impact
The vulnerability is an unauthenticated SQL Injection flaw (CWE-89) in the Smart Marketing SMS and Newsletters Forms plugin for WordPress. An attacker could inject arbitrary SQL statements through exposed form inputs, potentially retrieving sensitive data, modifying database records, or escalating to remote code execution if database privileges allow execution of underlying shell commands. The flaw exposes confidential information and can undermine the integrity of the site’s data.
Affected Systems
The affected product is the Smart Marketing SMS and Newsletters Forms plugin by Autorius E-goi, versions up to and including 5.1.24. Users running any of these versions are susceptible and should verify their installed version. No other WordPress plugins or core components are listed as affected.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is considered critical. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the lack of authentication and the high severity indicate a strong likelihood of exploitation. An attacker who can post data to the plugin’s form endpoints can trigger the injection without any credentials, making the attack vector public and straightforward.
OpenCVE Enrichment