Impact
The vulnerable WordPress plugin does not properly validate the pagination "offset" parameter before incorporating it into a SQL query. This omission allows a user with administrator privileges to inject malicious SQL code and execute arbitrary statements against the site’s database. The attacker can read, modify, or delete data, leading to potential data leakage or corruption. The weakness falls under the common category of SQL injection flaws.
Affected Systems
The flaw exists in the WPLP Cookie Consent WordPress plugin versions prior to 4.4.2. Any WordPress site running one of these vulnerable plugin versions is at risk, provided that an administrator account exists to submit the offset parameter.
Risk and Exploitability
An EPSS score of < 1% and a CVSS score of 4.1 suggest a modest likelihood and medium severity level for this vulnerability. The vulnerability is not listed in the CISA KEV catalog. Exploitability requires an administrator account capable of supplying the offset value. Although no public exploits have been reported, the SQL injection flaw could allow an attacker to read, modify, or delete data if they gain such privileged access.
OpenCVE Enrichment