Impact
Improper neutralization of special elements in an SQL command allows an attacker to perform blind SQL injection against the Persian Gravity Forms plugin. This flaw can enable the extraction of sensitive data, credential theft, or manipulation of database contents without authentication. The vulnerability arises from unsanitized input handling that is directly used in SQL queries.
Affected Systems
The issue affects the Persian Gravity Forms plugin (Hannan:گرویتی فرم فارسی) for WordPress, specifically all releases up to and including version 3.0.2. No other product variants or versions are listed as vulnerable.
Risk and Exploitability
The component carries a CVSS score of 7.6, indicating high severity, while its EPSS score is below 1%, indicating a low current likelihood of exploitation. The vulnerability is not present in the CISA KEV catalog. Based on the description, the attack vector is inferred to be a web‑based input submitted to the plugin, likely by an unauthenticated user. Successful exploitation would provide an attacker with read access to the underlying database, potentially exposing confidential data.
OpenCVE Enrichment