Impact
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before version 1.5.5 handles the id parameter without proper sanitisation or escaping before incorporating it into an SQL statement. A user who possesses a capability normally reserved for administrators can manipulate this parameter to inject arbitrary SQL, allowing the attacker to read, modify, or delete records stored in the WordPress database. The nature of the flaw is a classic SQL injection issue identified as CWE‑89.
Affected Systems
All WordPress sites that have installed the Database for Contact Form 7, WPforms, Elementor forms plugin with a version earlier than 1.5.5 are vulnerable. The affected product is the Database for Contact Form 7, WPforms, Elementor forms WordPress plugin, independent of the website size or hosting environment.
Risk and Exploitability
The CVSS score is 6.8, and the EPSS score is < 1%, which indicates a modest likelihood of exploitation. The flaw is exploitable only by a user who possesses a capability that is granted to administrators by default but can be delegated to lower privileged roles. The likely attack vector is through authenticated web requests to the plugin’s id parameter, which is presumably exposed via the WordPress administrative interface. Though not listed in the CISA KEV catalog, the potential for unauthorized database manipulation makes the risk significant once an attacker gains the required permissions. It is advisable to monitor accounts with form‑related capabilities and to apply fixes promptly.
OpenCVE Enrichment