Impact
Improper neutralization of special elements within SQL commands in the W4 Post List plugin permits attackers to inject malicious SQL through exposed input fields, resulting in blind SQL injection. This overflow can expose sensitive database contents, potentially allowing unauthenticated users to retrieve or manipulate confidential data.
Affected Systems
The W4 Post List plugin produced by Shazzad Hossain Khan is vulnerable in all releases up to and including version 3.0.6. Any WordPress installation using these versions is affected.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity vulnerability. Although EPSS data is unavailable, the absence from the CISA KEV list suggests no confirmed widespread exploitation yet; however, attackers can exploit the blind injection via unauthenticated HTTP requests, requiring only crafted input to remote the database. The risk remains significant, especially for sites that rely on the exposed plugin features.
OpenCVE Enrichment