Impact
The Album Cover Finder WordPress plugin up to version 0.7.0 suffers from an unauthenticated SQL injection flaw where the 'and_action' parameter is not properly sanitized before being used in a database query. Attackers who need no credentials can inject arbitrary SQL, potentially revealing sensitive database contents or altering site data, resulting in a data breach.
Affected Systems
The vulnerability affects any WordPress site that has the Album Cover Finder plugin installed, with affected versions through 0.7.0. The product is identified by the CNA as 'Unknown:Album Cover Finder', with no additional vendor or version details provided beyond the plugin name and major release number.
Risk and Exploitability
The lack of input validation creates an unauthenticated attack surface that can be exploited remotely by crafting a URL containing a malicious 'and_action' value. The CVSS score is 8.6, indicating a high severity, while the EPSS score is below 1%, suggesting a low overall probability of exploitation. The flaw is not listed in CISA's KEV catalog.
OpenCVE Enrichment