Impact
An unauthenticated attacker can inject arbitrary SQL through the WordPress Verified Reviews (Avis Vérifiés) plugin functions. The flaw allows read, modification, or deletion of database records, potentially exposing sensitive data or corrupting application integrity. The weakness maps to CWE-89, representing improper sanitization of untrusted input in database queries.
Affected Systems
The vulnerability affects all instances of the Verified Reviews (Avis Vérifiés) plugin released by Par avisverifies with version numbers 2.4.6 and earlier. Site administrators should verify the plugin version installed and confirm whether an upgrade is available from the vendor.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. While no EPSS value is provided, the lack of a KEV listing does not diminish the impact; the flaw is exploitable without authentication, likely via an HTTP request to a plugin endpoint. Attackers with internet access to the site can trigger the injection simply by crafting a request, making the risk high for sites running the affected plugin.
OpenCVE Enrichment