Impact
The Tz Weekly Radio Schedule WordPress plugin up to version 1.8.1 fails to sanitize an input before using it in a SQL query. The vulnerable AJAX action, available to visitors who are not logged in, permits attackers to inject arbitrary SQL code. This flaw is a classic injection vulnerability (CWE-89) and could enable the extraction of confidential database information, impacting confidentiality and possibly allowing further exploitation if the database contains credential material.
Affected Systems
WordPress installations that have the Tz Weekly Radio Schedule plugin of version 1.8.1 or earlier deployed. The plugin is not tied to a major commercial vendor; it is listed as Unknown:Tz Weekly Radio Schedule in the CNA record.
Risk and Exploitability
The CVSS score of 8.6 classifies the flaw as high severity, while the EPSS score of less than 1 % indicates that, at present, the probability of exploitation is low. The flaw is not in the CISA KEV list, so no known public exploit is documented. Attackers can trigger the vulnerability by accessing the AJAX endpoint without authentication, making the attack vector readily reachable to anyone on the internet. Even with a low exploitation probability, the potential for data loss justifies prompt remediation.
OpenCVE Enrichment