Impact
The BuildKit WordPress plugin before 1.0.29 fails to sanitize and escape data submitted by contributor‑level users. The list_content parameter is stored directly and later incorporated into a database query without proper escaping. A malicious contributor can inject SQL that executes when the stored content is published and viewed by any visitor, potentially exposing, modifying, or deleting data in the site database.
Affected Systems
Any WordPress installation using the BuildKit plugin version earlier than 1.0.29 is affected. The vulnerability exists in the plugin code managing the list_content field and requires that a user has the Contributor role.
Risk and Exploitability
Because the flaw is a stored SQL injection, exploitation requires the attacker to have contributor privileges, which is a relatively low‑privilege level commonly granted for content authors. Once injected, the associated SQL runs with the privileges of the web application’s database user. No public exploit is reported, and the EPSS score is not available, making it uncertain how often the vulnerability will be targeted. The lack of a KEV designation means no known public exploitation has been documented. Nonetheless, the high potential impact and availability of an unauthenticated view endpoint make this a high‑risk issue, especially in environments with sensitive data.
OpenCVE Enrichment