Impact
The vulnerability arises from improper neutralization of special elements in SQL commands within the WordPress Contact Form 7 Database – CFDB7 plugin (version 1.0.0 and earlier). This flaw allows an attacker to inject arbitrary SQL statements through form inputs, enabling unauthorized reading, modification, or deletion of database contents. The weakness is identified as CWE-89, a classic SQL injection flaw that directly threatens the confidentiality and integrity of sensitive data stored by the plugin.
Affected Systems
The affected product is the Contact Form 7 Database – CFDB7 endpoint of the penguinarts WordPress plugin. Versions 1.0.0 and older are vulnerable; no other product versions are listed as affected.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity vulnerability, and the EPSS score of <1% suggests that, while exploitation is currently considered unlikely, it remains possible. Based on the description, attackers can likely exploit the flaw by submitting specially crafted form data or manipulating HTTP requests directed at the plugin’s processing endpoint.
OpenCVE Enrichment
EUVD