Impact
The vulnerability in OptinCraft arises from insufficient escaping of the 'order_by' parameter, allowing authenticated administrators to inject arbitrary SQL. This flaw permits the execution of additional queries within the same request, potentially disclosing sensitive database content. The weakness is a classic SQL injection flaw (CWE‑89).
Affected Systems
WordPress sites using the OptinCraft – Drag & Drop Optins & Popup Builder plugin version 1.2.0 or earlier, including the 1.0.2 tag referenced in the plugin's codebase.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate risk level, and EPSS is not available, so there is no current evidence of widespread exploitation. The vulnerability requires legitimate administrator access, so attackers need to first gain or possess such credentials. Since the flaw can be triggered via the web interface, it is remote on the staging or production environment. The flaw is not listed in CISA’s KEV catalog, but mitigated by reducing attack surface from the administrator account.
OpenCVE Enrichment