Impact
The Post Voting System WordPress plugin up to and including version 1.0 fails to properly sanitize the 'row' parameter before including it in a SQL query, allowing any authenticated user to inject arbitrary SQL code. This flaw can enable an attacker to read, modify, or delete arbitrary database records, potentially exposing sensitive site data or disrupting site functionality. The impact is on data confidentiality and integrity, with possible availability consequences if critical data is altered.
Affected Systems
The vulnerability applies to the Post Voting System WordPress plugin whose versions do not exceed 1.0, with the vendor listed as Unknown:Post Voting System.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, which suggests that widespread exploitation has not been observed yet. However, the presence of a classic SQL injection flaw and the fact that it can be triggered by any authenticated user means that exploitation is technically feasible and would not require special privileges beyond normal plugin usage. In the absence of an available CVSS score, administrators should treat this as a high‑risk flaw because of the ease of exploitation and the potential for serious data compromise.
OpenCVE Enrichment