Impact
The Tz Weekly Radio Schedule WordPress plugin through version 1.8.1 does not sanitize or escape the 'week' parameter used in a vulnerable AJAX action, allowing attackers to inject arbitrary SQL statements and read sensitive database content. This flaw is a classic input validation weakness classified as CWE-89 and can result in unauthorized disclosure of user data, site configurations, and potentially full database compromise.
Affected Systems
The vulnerability affects the WordPress plugin Tz Weekly Radio Schedule versions up to and including 1.8.1. There are no other vendors or products listed; the issue is specific to this plugin as noted by the CWE entry.
Risk and Exploitability
The CVSS score of 8.6 highlights a high severity for a vulnerability that could allow an unauthenticated attacker to inject SQL via the 'week' parameter. The EPSS score of less than 1% suggests that, at the time of analysis, the likelihood of exploitation is low. The flaw is not listed in CISA KEV. Based on the description, the vulnerable AJAX endpoint can be accessed by anyone over HTTP without authentication, indicating a remote attack vector.
OpenCVE Enrichment