Impact
The Quentn WP WordPress plugin before version 1.2.15 contains an unsanitised 'orderby'/'order' parameter that is inserted directly into an SQL query. Administrators can exploit this to inject arbitrary SQL commands, enabling data exfiltration, modification, or deletion. The vulnerability allows attackers with high privileges to compromise database confidentiality, integrity, and availability, potentially leading to full site compromise.
Affected Systems
Any WordPress installation that uses the Quentn WP plugin at a version lower than 1.2.15 is affected. The plugin, provided by an unknown vendor, is typically found in WordPress sites as a plugin named Quentn WP.
Risk and Exploitability
Because the flaw requires an account with administrator rights to manipulate the vulnerable parameters, the attack vector is primarily local within the application, but once exploited an attacker can execute arbitrary SQL directly against the database. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV. The CVSS score of 4.1 indicates a low severity, suggesting that the risk level is moderate rather than critical in this privileged context.
OpenCVE Enrichment