Impact
This vulnerability allows an attacker with contributor-level access on a vulnerable WordPress site to inject arbitrary SQL code into the WPBulky plugin. The flaw enables manipulation of the database, potentially exposing, modifying, or deleting data, which can compromise the confidentiality and integrity of the site content. The weakness is a classic SQL Injection flaw identified by CWE-89.
Affected Systems
The affected product is the WPBulky community plugin developed by VillaTheme. Versions up to and including 1.2.2 are vulnerable. Any WordPress installation that has this plugin version installed could be impacted.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. No EPSS score is provided, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely requires a user to have contributor or higher privileges on the site, but once authenticated, injection can be performed through the plugin’s input handling. Given the severity, a timely update is strongly recommended.
OpenCVE Enrichment