Impact
The Social Web Suite WordPress plugin up to version 4.1.12 fails to require the shared secret before processing authorization requests and does not sanitize a query parameter used in an SQL statement. Unauthenticated users can therefore send crafted requests that result in blind SQL injection, enabling them to read or modify database contents and potentially compromise the confidentiality and integrity of the site.
Affected Systems
WordPress sites running the Social Web Suite plugin version 4.1.12 or earlier are affected. The vulnerability exists in the plugin's handling of authentication requests, regardless of the shared secret setting.
Risk and Exploitability
Because the flaw is exploitable without authentication and no secret is required, any remote user can invoke the vulnerable endpoint. No public exploits are currently documented and the EPSS score is not available; however, the absence of a KEV listing does not remove the risk. The attack vector is inferred to be remote over HTTP(S) due to the nature of a WordPress plugin. The potential impact includes unauthorized data exfiltration and data modification, with a high likelihood of exploitation if the attacker can enumerate the vulnerable endpoint.
OpenCVE Enrichment