Impact
The vulnerability allows malicious crafts to insert arbitrary SQL statements into the Easy Digital Downloads shop manager functionality, enabling unauthorized read, modification, or deletion of database contents through CWE-89. An attacker who successfully exploits the flaw could obtain sensitive order data, user credentials, or inject malicious data. The description does not state the ability to execute remote code, but the impact is confined to data confidentiality and integrity.
Affected Systems
The affected product is the Easy Digital Downloads plugin, published by Syed Balkhi. Versions 3.7.0 and earlier are affected. Users running any of these versions with the shop manager enabled are susceptible.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity exposure. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no publicly confirmed exploit at the time of this analysis. The likely attack vector is through the shop manager web interface; the description infers that an authenticated or unauthenticated user who can send crafted requests to the plugin endpoints could exploit the flaw, though authentication requirements are not explicitly detailed. This means the risk may be mitigated if shop manager access is tightly controlled.
OpenCVE Enrichment