Impact
The WordPress plugin 'WP Shortcut Link' (advertisement banner) up to version 1.2.0 fails to sanitize an input parameter that is then concatenated into an SQL query within an AJAX action. Because this action is available to all visitors, attackers can inject SQL through a crafted URL and retrieve arbitrary data from the database. The flaw permits compromise of confidentiality and potentially integrity, but is not documented as a remote code execution vulnerability.
Affected Systems
Any WordPress installation that has the 'WP Shortcut Link' plugin version 1.2.0 or earlier installed is affected. No other vendors or versions are listed, and the vulnerability is specifically tied to the plugin's AJAX endpoint.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity impact. The EPSS score is lower than 1%, suggesting a low probability of exploitation in the wild, and the flaw is not present in CISA’s KEV catalog. Nevertheless, because the endpoint is unauthenticated, the attack vector is straightforward: send a crafted request to the AJAX action to extract data. Effective exploitation requires the code to reach the vulnerable query, which is a direct input concatenation vulnerable to SQL injection.
OpenCVE Enrichment