Impact
This vulnerability is an SQL injection flaw that permits an attacker to execute arbitrary SQL queries against the WordPress database. The flaw arises from improper neutralization of special characters in user input that is incorporated into SQL commands. If exploited, an attacker could read, modify, or delete data stored in the site’s database, potentially compromising confidential information and affecting site integrity.
Affected Systems
The affected product is DevItems HashBar – WordPress Notification Bar plugin through version 2.0.3. Administrators using any of these releases should review installed plugin versions to determine if an upgrade is required.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, and although EPSS data is unavailable, the lack of mention in CISA’s KEV catalog suggests no known widespread exploitation yet. However, the blind nature of the injection means an attacker only needs to read the response code to confirm the vulnerability, increasing the risk of unnoticed attacks. The likely attack vector is web requests to the plugin’s endpoints, which could be triggered remotely without authentication.
OpenCVE Enrichment