Impact
An unauthenticated attacker can exploit the search functionality of the SPS‑Suite WordPress plugin to inject malicious SQL statements. The vulnerability arises because the plugin fails to sanitize user input before incorporating it into a database query. If an attacker controls the search string, they could read sensitive data from the database, modify records, or even delete tables, depending on database privileges. The impact is the potential compromise of confidentiality and integrity of data stored by the WordPress site.
Affected Systems
All sites running the SPS‑Suite plugin version 1.4.0 or older are affected. The vulnerability is tied specifically to the static‑page search feature that has not been patched up to and including version 1.4.0.
Risk and Exploitability
The attack vector is a direct, unauthenticated web request to the search endpoint. Because the vulnerability is a pure SQL injection, exploitation requires only that the attacker can reach the search page, which most WordPress sites expose publicly. No authentication or elevated privileges are needed. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting that public exploitation may be low or insufficient data on exploitation volume is available. Nonetheless, the absence of a known fix in the current version makes this a high‑risk exposure for any site regardless of current exploitation statistics.
OpenCVE Enrichment