SQL Injection Vulnerability in Contact Form 7 Database by PenguinArts
CVE-2025-22351

7.6HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
7 January 2025

Summary

A SQL Injection vulnerability exists in PenguinArts' Contact Form 7 Database – CFDB7, which allows attackers to manipulate SQL queries by injecting malicious input. This could lead to unauthorized access to sensitive data stored in the database. The flaw affects versions from n/a through 1.0.0, making it essential for users to update their installations to protect against potential data breaches and attacks.

Affected Version(s)

Contact Form 7 Database – CFDB7 <= 1.0.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.