Impact
cmsMinds Pay with Contact Form 7 allows an attacker to inject SQL commands through improperly sanitized input in the plugin’s contact form. The flaw is a classic SQL injection (CWE-89) that could enable read, modify or delete operations against the site’s database, potentially leaking sensitive user data or compromising site integrity.
Affected Systems
WordPress sites running the cmsMinds Pay with Contact Form 7 plugin with a version of 1.0.4 or earlier are affected. Versions newer than 1.0.4 are not known to be vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity vulnerability with a moderate to high likelihood of exploitation. The EPSS score of less than 1% suggests the probability of a real‑world exploit at this time is low, and the issue is not listed in the CISA KEV catalog. Externally accessible form input provides the attack vector; no local privilege escalation or authentication is required. An attacker who can submit crafted form data could obtain confidential database contents or disrupt site functionality.
OpenCVE Enrichment
EUVD