Impact
The Quentn WP WordPress plugin prior to version 1.2.15 contains a vulnerability where a request parameter named 'qntn_wp' is not properly escaped before being used in an unprepared SQL query. This omission permits SQL injection, allowing an unauthenticated attacker to craft malicious input that can extract or manipulate arbitrary data stored in the database. The affected systems could therefore expose sensitive information such as user credentials, content, or configuration details without any authentication or authorization barriers.
Affected Systems
The vulnerability affects the Quentn WP plugin for WordPress, specifically versions 1.2.13 and 1.2.14. Based on the description, it is inferred that earlier releases that include the same code path may also be affected.
Risk and Exploitability
Attackers can execute arbitrary SQL through the unescaped 'qntn_wp' parameter with no authentication and a simple HTTP request. The CVSS score of 8.6 highlights a high severity risk. The EPSS score of less than 1% suggests a low probability of exploitation, while the vulnerability remains absent from CISA's KEV catalog. Nonetheless, the potential for data extraction persists on impacted WordPress installations.
OpenCVE Enrichment