Impact
The Product Question and Answer WordPress plugin through version 1.1.0 does not sanitize the p_id and read parameters used in AJAX actions, allowing an unauthenticated attacker to inject SQL and extract database contents. The impact is the unauthorized disclosure of sensitive data; the flaw is a classic SQL injection vulnerability identified as CWE-89. No evidence indicates that the injection can lead to code execution or other privileges beyond data extraction.
Affected Systems
WordPress sites using the Product Question and Answer plugin version 1.1.0 or earlier. No other vendors or product versions are explicitly listed. The vulnerability affects every installation that has the plugin enabled and the AJAX endpoints exposed to unauthenticated users.
Risk and Exploitability
Based on the description, it is inferred that the attacker can send a crafted AJAX request to the plugin's public endpoints, using unsanitized p_id and read parameters as the likely attack vector to extract database contents. The CVSS score of 8.6 classifies the vulnerability as High, indicating significant potential impact if exploited. The EPSS score is reported as less than 1%, suggesting a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, which further indicates it is not currently a known target of large-scale attacks.
OpenCVE Enrichment