Impact
An improper neutralization of special elements in SQL statements allows an attacker to perform blind SQL injection against the WordPress UpSolution Core plugin. This injection can be used to read, modify, or delete sensitive data stored in the database, or in the worst case, execute arbitrary SQL commands that could compromise the database. This vulnerability is classified under CWE‑89 and carries a CVSS score of 8.5, indicating a high severity risk to confidentiality, integrity, and potentially availability of affected systems.
Affected Systems
The UpSolution UpSolution Core WordPress plugin is affected for all releases from the earliest available version up through 9.3 inclusive. Users who have the plugin installed at versions 9.3 or earlier are vulnerable. The recommendation is to upgrade to at least version 9.3.1, the first release to include the fix.
Risk and Exploitability
The exploitability of this flaw is considered high, though the EPSS score is not available. The lack of a KEV listing does not diminish the risk posed by the high CVSS score. The vulnerability is a blind injection, meaning an attacker would need to infer data through query response characteristics. Attackers could craft malicious input via form fields or URLs that the plugin processes, thereby injecting crafted SQL that the backend executes. Successful exploitation could allow data exfiltration or elevation of privilege within the database.
OpenCVE Enrichment