Impact
This vulnerability is a classic blind SQL injection caused by the Pixel WordPress Form BuilderPlugin & Autoresponder failing to properly escape user input before embedding it in an SQL command. As the flaw falls under CWE-89, an attacker can manipulate query parameters to extract sensitive database information through timing or error-based techniques without receiving immediate error feedback. The lack of proper input validation allows an adversary to read and potentially modify data, with the risk of escalating to remote code execution if additional downstream vulnerabilities are present.
Affected Systems
The affected product is the kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder, version 1.0.2 and earlier. No other vendors or product versions are listed as affected.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, accessed through the plugin’s form interface, and likely requires the ability to submit specially crafted input to the vulnerable endpoint. An attacker could potentially exfiltrate data and, depending on additional weaknesses, achieve broader compromise.
OpenCVE Enrichment
EUVD