SQL Injection Vulnerability in Contact Form 7 Database by PenguinArts
CVE-2025-22351
7.6HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 7 January 2025
Summary
A SQL Injection vulnerability exists in PenguinArts' Contact Form 7 Database – CFDB7, which allows attackers to manipulate SQL queries by injecting malicious input. This could lead to unauthorized access to sensitive data stored in the database. The flaw affects versions from n/a through 1.0.0, making it essential for users to update their installations to protect against potential data breaches and attacks.
Affected Version(s)
Contact Form 7 Database – CFDB7 <= 1.0.0
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)