Impact
The vulnerability is a classic SQL injection flaw in the WP EasyCart plugin before version 5.9.4. An attacker can supply malicious input that bypasses the plugin’s input validation and injects arbitrary SQL, enabling the retrieval, alteration, or removal of data stored in the WordPress database. This can compromise the confidentiality and integrity of site content and user information.
Affected Systems
The flaw affects the WP EasyCart plugin by levelfourdevelopment (WordPress plugin) in all releases up to and including 5.9.4. No further sub‑version details are supplied beyond the version threshold.
Risk and Exploitability
The CVSS score of 8.5 signals high severity. EPSS data is unavailable, so the exact likelihood of exploitation cannot be measured, though the attack is not yet reported in CISA’s KEV list. The most likely attack vector is through crafted HTTP requests directed at the plugin’s exposed endpoints; this inference comes from the nature of SQL injection in web applications. Prompt remediation is advised to mitigate potential data loss or corruption.
OpenCVE Enrichment