Impact
SAMO Forms WordPress plugin versions up to and including 1.0.0 fails to properly sanitize and escape user input before forming SQL queries in several unauthenticated actions. This flaw enables an attacker without authentication to inject arbitrary SQL commands, potentially extracting sensitive data, altering stored information, or compromising the entire database. No post‑exploitation code execution is required; the risk is limited to data integrity and confidentiality.
Affected Systems
Any WordPress site that has SAMO Forms plugin version 1.0.0 or older installed. No specific build numbers beyond the major/minor version are listed, so all releases of the plugin before 1.0.1 are vulnerable.
Risk and Exploitability
The vulnerability can be exploited remotely without user interaction, giving attackers direct access to the database layer. Although a publicly available exploit is not cited and the EPSS score is unavailable, the absence of authenticating requirements combined with the high-impact consequence classifies the risk as high. The vulnerability is not listed in the CISA KEV catalog, but its potential for data compromise warrants urgent attention.
OpenCVE Enrichment