What the vulnerability does
01Description
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
What the vulnerability does
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
Explanation of Vulnerability in Simple Terms
The Cryptocurrency Widgets Pack contains a SQL injection vulnerability that allows unauthenticated attackers to query the site's database directly. No user interaction is required. An attacker can extract sensitive data, modify database records, or disrupt site availability. The vulnerability affects all versions up to 1.8.1.
What an attacker can do
Query or modify the site database and extract sensitive information without authentication.
Potential impact on your site
Attackers can steal user data, modify content, or take the site offline without needing a login.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities