Impact
The vulnerability arises from a SQL injection flaw in the Live Copy Paste for Elementor plugin up to version 1.5.10. An attacker can inject arbitrary SQL statements through the contributor input, leading to unauthorized data exposure or modification. This is a classic CWE‑89 input validation weakness that permits attackers to compromise the confidentiality and integrity of the WordPress site's database.
Affected Systems
WordPress Live Copy Paste for Elementor plugin version 1.5.10 and earlier. The affected vendor is bdthemes, with the public name Live Copy Paste for Elementor – the plugin should be updated or removed.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is not available, so the global likelihood of exploitation is unknown, but the vulnerability is not listed in the CISA KEV catalog. The plugin exposes a web‑accessible form that accepts contributor input; therefore the attack vector is likely remote via the WordPress administration interface. An attacker would need at least contributor‑level access to supply the malicious payload, but if the plugin incorrectly escalates privileges, a lower role could suffice.
OpenCVE Enrichment