Impact
The vulnerability is a blind SQL injection flaw in jegtheme's WordPress JNews - Pay Writer plugin. Improper neutralization of user input in SQL commands allows an attacker to manipulate database queries, resulting in unauthorized data disclosure, modification or deletion. This could compromise the confidentiality, integrity, or availability of the application’s data assets.
Affected Systems
WordPress sites running jegtheme JNews - Pay Writer plugin version 12.0.1 or earlier are affected. The issue exists across all installations of the plugin up to and including the 12.0.1 release, regardless of the WordPress version or other plugins installed. Sites that have not updated to 12.0.2 or later remain vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a high‑severity vulnerability. The EPSS score is not available, but the lack of mitigation means attackers can likely exploit the flaw remotely through any user input accepted by the plugin. The KEV status is not listed, indicating no confirmed public exploits yet. Based on the plugin’s documented input handling, the likely attack vector is remote, utilizing externally supplied parameters that are embedded directly in SQL statements. Exploitation requires no elevated privileges on the server, making it accessible to anyone who can interact with the vulnerable plugin interface.
OpenCVE Enrichment