Impact
The plugin contains a classic SQL injection flaw that allows a malicious contributor to insert arbitrary SQL commands through unsanitized form input. An attacker could read, modify or delete any data stored in the WordPress database, potentially corrupting transaction records, exposing sensitive user information, or injecting malicious code that could further compromise the site.
Affected Systems
The vulnerable product is WordPress Mollie Forms distributed by Nick van Wobbie. All installations running version 2.11.0 or earlier are affected; versions 2.11.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, yet the EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting exploitation is plausible but not certain. The most likely attack vector is through a malicious or compromised contributor who can submit data via the plugin’s forms. Because the flaw is exercised through normal form entry, any site that authorizes contributors to use Mollie Forms is at risk; no special network conditions are required.
OpenCVE Enrichment