Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.
Published: 2026-07-13
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special elements in an SQL command allows an attacker to perform blind SQL injection against the Persian Gravity Forms plugin. This flaw can enable the extraction of sensitive data, credential theft, or manipulation of database contents without authentication. The vulnerability arises from unsanitized input handling that is directly used in SQL queries.

Affected Systems

The issue affects the Persian Gravity Forms plugin (Hannan:گرویتی فرم فارسی) for WordPress, specifically all releases up to and including version 3.0.2. No other product variants or versions are listed as vulnerable.

Risk and Exploitability

The component carries a CVSS score of 7.6, indicating high severity, while its EPSS score is below 1%, indicating a low current likelihood of exploitation. The vulnerability is not present in the CISA KEV catalog. Based on the description, the attack vector is inferred to be a web‑based input submitted to the plugin, likely by an unauthenticated user. Successful exploitation would provide an attacker with read access to the underlying database, potentially exposing confidential data.

Generated by OpenCVE AI on August 1, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Persian Gravity Forms to a version newer than 3.0.2 to remove the vulnerable code.
  • Deploy a web application firewall and configure it to block or filter typical SQL injection payloads targeting the plugin’s input points.
  • Ensure that all user‑supplied data handled by the plugin is properly escaped or parameterized in accordance with CWE‑89 best practices, and review database permissions to enforce least privilege for application accounts.

Generated by OpenCVE AI on August 1, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Hannan
Hannan گرویتی فرم فارسی
Wordpress
Wordpress wordpress
Vendors & Products Hannan
Hannan گرویتی فرم فارسی
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.
Title WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Hannan گرویتی فرم فارسی
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:14:55.632Z

Reserved: 2026-07-13T06:13:44.978Z

Link: CVE-2026-61955

cve-icon Vulnrichment

Updated: 2026-07-13T13:14:51.943Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')