Impact
The affected WordPress plugin performs insufficient escaping on the user‑supplied input provided in the ‘data[queryCondition]’ parameter, allowing an adversary with administrator or higher privileges to inject arbitrary SQL fragments into existing queries. The injection can be used to retrieve sensitive database contents. The weakness is a classic SQL injection (CWE‑89).
Affected Systems
Any installation of the Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress whose version is 3.2.0 or earlier. The vendor, bitpressadmin, retains responsibility for the plugin’s update cycle.
Risk and Exploitability
The score of 6.5 on the CVSS vector indicates a high potential impact. The exploitation requires authentication with administrator‑level access; the attack vector is an authenticated web request, so the attacker must already have valid credentials or compromise an admin account. No EPSS value is available, so the current exploitation probability is unclear, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment