SQL Injection Vulnerability in GoZen Forms Plugin for WordPress
CVE-2025-6782
What is CVE-2025-6782?
The GoZen Forms plugin for WordPress has a vulnerability allowing SQL Injection through the 'forms-id' parameter in the dirGZActiveForm() function. This security flaw is present in all versions up to and including 1.1.5. Due to insufficient escaping of user-supplied input and lack of proper preparation of the SQL query, unauthenticated attackers could exploit this weakness. By injecting additional SQL queries into existing ones, an attacker could potentially gain access to sensitive database information, thereby compromising the security of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GoZen Forms * <= 1.1.5
References
CVSS V3.1
Timeline
Vulnerability published