Impact
The vulnerability in Themeum WP Mega Menu allows attackers to inject SQL commands through unsanitized input fields, leading to blind SQL injection. Because the plugin fails to properly neutralize special elements, an attacker can deduce database contents or modify data without direct error messages. This weakness grants unauthorized read or modification of the database, potentially compromising sensitive information stored in the WordPress site.
Affected Systems
WordPress users running the WP Mega Menu plugin version 1.4.2 or earlier are impacted. The plugin, provided by Themeum, is available for WordPress sites that have installed or updated the plugin within that version range. The vulnerability applies from the earliest release through 1.4.2, and patching to a later version beyond 1.4.2 removes the issue.
Risk and Exploitability
The CVSS score of 7.6 indicates serious severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to trigger the plugin’s input fields, which may be accessible to authenticated users or public users depending on the plugin configuration, to execute the injection. Given the blind nature of the attack, exploitation requires iterative querying and may involve column enumeration or time delays. If successful, the attacker could extract or alter database records, leading to data loss, exposure, or site compromise.
OpenCVE Enrichment