Impact
The Music Store plugin does not sanitize or escape user‑supplied data before embedding it in an SQL query. An unauthenticated attacker can craft a request to the paypal-data handler that injects SQL code, allowing arbitrary database queries, data exfiltration, or damage. The flaw directly compromises confidentiality and integrity of the site’s database.
Affected Systems
All WordPress sites running the Music Store eCommerce plugin version 1.4.4 or earlier are affected. The vulnerability is present in every build prior to 1.4.5, regardless of other plugins or themes.
Risk and Exploitability
No EPSS score is publicly available and the vulnerability is not listed in the CISA KEV catalogue. The CVSS score is not provided, but based on the description it is a high‑severity SQL injection that requires no authentication. An attacker can exploit it by sending a specially crafted request to the plugin’s paypal‑data endpoint; no special configuration is required. The lack of input filtering makes exploitation straightforward once the target URL is known.
OpenCVE Enrichment