PT-2025-29211 · WordPress · Gb Forms Db

Alexander Chikaylo

·

Published

2025-07-11

·

Updated

2025-07-11

·

CVE-2025-5392

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: GB Forms DB plugin for WordPress versions up to and including 1.0.2
Description: The GB Forms DB plugin for WordPress is susceptible to Remote Code Execution via the gbfdb talk to front() function. The function accepts user input and passes it through call user func(), allowing unauthenticated attackers to execute code on the server. This could enable attackers to inject backdoors or create new administrative user accounts.
Recommendations: Update the GB Forms DB plugin to a version beyond 1.0.2.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5392

Affected Products

Gb Forms Db