SQL Injection Vulnerability in Kofimokome Message Filter for Contact Form 7
CVE-2025-46252

7.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 April 2025

What is CVE-2025-46252?

The Kofimokome Message Filter for Contact Form 7 has an SQL Injection vulnerability that allows attackers to manipulate SQL queries by injecting malicious SQL code. This can lead to unauthorized access and potential data breach risks, affecting the integrity of the database. The issue is present in versions from n/a through 1.6.3.2. It is crucial for users to ensure they are using patched versions of this plugin to maintain secure contact form functionalities.

Affected Version(s)

Message Filter for Contact Form 7 0 <= 1.6.3.2

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock (Patchstack Alliance)
.