Left unpatched, this chain allows a fully unauthenticated attacker to:
Confirm the SQL injection with no credentials
Escalate to arbitrary administrator account creation
Upload a plugin and execute commands on the server
Fully compromise the site with no prior access