Impact
A parameter handled by the Site Setup Wizard WordPress plugin is used directly in a SQL statement without proper sanitisation or escaping, enabling attackers who need no authentication to inject statements and read data from the database. The impact is the disclosure of all database contents the plugin’s database user can access, potentially including user credentials, site content, and configuration information.
Affected Systems
The vulnerability affects the Site Setup Wizard WordPress plugin version 1.5.8 and earlier. The plugin is listed under an unknown vendor, but any WordPress installation using this plugin build should be considered exposed.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV. Because authentication is not required and the flaw permits data extraction, the theoretical risk is high, but the lack of an EPSS rating means the current exploitation probability is uncertain. Without a CVSS score definition, the severity cannot be quantified precisely, yet any attacker with network access to the site could exploit the flaw as soon as the plugin is installed or kept at the vulnerable version.
OpenCVE Enrichment