Impact
The vulnerable WordPress plugin does not properly validate the pagination "offset" parameter before incorporating it into a SQL query. This omission allows a user with administrator privileges to inject malicious SQL code and execute arbitrary statements against the site’s database. The attacker can read, modify, or delete data, leading to potential data leakage or corruption. The weakness falls under the common category of SQL injection flaws.
Affected Systems
The flaw exists in the WPLP Cookie Consent WordPress plugin versions prior to 4.4.2. Any WordPress site running one of these vulnerable plugin versions is at risk, provided that an administrator account exists to submit the offset parameter.
Risk and Exploitability
No EPSS score is currently available for this vulnerability, and it is not listed in the CISA KEV catalog. The exploitability hinges on the existence of a privileged administrator account that can supply the offset value. While no public exploits have been reported, the nature of SQL injection makes the potential damage significant if an attacker can gain such access.
OpenCVE Enrichment