CVE-2020-11530 is a critical blind SQL injection vulnerability affecting the Chop Slider 3 WordPress plugin. This flaw, located in the 'id' GET parameter of get_script/index.php, allows unauthenticated attackers to execute arbitrary SQL queries against the WordPress database. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, the vulnerability poses a significant risk of full data compromise. While not currently on the CISA KEV list, public exploit code exists in Metasploit and ExploitDB, and Nuclei templates are available, suggesting a high potential for exploitation despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:idangero:chop_slider:3.0:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.