Impact
Untrusted input from the username request parameter is incorporated directly into an SQL query by the Yo plugin (versions 1.1 through 1.3.1) without sanitization or parameterization. This flaw enables SQL injection, allowing an attacker to read any table in the WordPress database, including password hash columns, thus compromising credential confidentiality and potentially leading to further compromise.
Affected Systems
The vulnerability affects the Yo WordPress plugin across all releases from version 1.1 up to 1.3.1. The vendor is not specified beyond the general "Yo" label, and no specific WordPress core or operating system versions are listed, so any WordPress installation hosting these plugin versions is affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is below 1%, suggesting that exploitation is currently unlikely, but the lack of KEV listing does not eliminate the risk. Attackers can trigger the vulnerability simply by sending an unauthenticated HTTP request to the plugin’s endpoint that contains the username parameter, and the injection can be used to extract arbitrary data, especially passwords. Based on the potential for credential compromise, it is inferred that an attacker could use those credentials to cause outages, exfiltrate data, or pivot to other systems, but these specific outcomes are not explicitly documented in the CVE description.
OpenCVE Enrichment