This vulnerability is highly dangerous and expected to become exploited.
Due to the specific nature of this vulnerability, no virtual patch can be assigned to it.
This could allow a malicious actor to directly interact with your database, including but not limited to stealing information.
CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.
We advise to mitigate or resolve the vulnerability immediately.
Published by Patchstack
15 Oct, 2025