Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.3%