Impact
The vulnerability is an unauthenticated SQL Injection in the WordPress Product Filter by WBW plugin (versions 3.1.7 and earlier). It allows an attacker to inject malicious SQL statements into the plugin’s database queries, potentially enabling arbitrary data retrieval or manipulation.
Affected Systems
Affected by default on WordPress sites using the Product Filter by WBW plugin version 3.1.7 or older. No other products or versions are listed as affected.
Risk and Exploitability
The flaw scores a CVSS of 9.3, reflecting its high severity. No EPSS score is available, but the lack of a KEV listing suggests no publicly confirmed exploits yet. The request that does not require authentication, so any user can exploit the flaw.
OpenCVE Enrichment