Impact
The Easy Form Builder plugin contains a flaw where user input is not properly escaped before being used in SQL commands. This exposes the site to blind SQL injection, which can allow an attacker to retrieve sensitive data or modify database contents, possibly exfiltrating personal information or other confidential data stored in the WordPress database. The vulnerability is classified as CWE-89.
Affected Systems
WordPress sites that use the Easy Form Builder plugin version 3.8.15 or earlier. The affected vendor is hassantafreshi, and the product is the Easy Form Builder plugin.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, although the EPSS score is below 1%, suggesting low exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is web-based, exploiting the plugin’s form handling functionality via crafted HTTP requests.
OpenCVE Enrichment
EUVD