Impact
The Eventer plugin for WordPress, versions up to 4.4.2, is vulnerable to a time-based SQL injection through the 'code' parameter. Because the plugin fails to escape the user-supplied value and does not use prepared statements, an attacker can append arbitrary SQL to permit unauthenticated attackers to read or manipulate data stored in the WordPress database – a classic SQL injection vulnerability (CWE-89).
Affected Systems
WordPress sites that have the Eventer plugin by joe007 installed at version 4.4.2 or earlier are affected. The plugin is used for event management within WordPress environments.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity. The EPSS score is less than 1%, implying a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector requires no user authentication and can be carried out through the public web interface. An attacker who can reach the site can send a crafted request to the vulnerable endpoint and extract sensitive data, making confidentiality a significant risk.
OpenCVE Enrichment