PT-2025-5089 · WordPress · Contact Form 7 Round Robin Lead Distribution

João Pedro S Alcântara

·

Published

2025-01-22

·

Updated

2025-01-22

·

CVE-2025-23784

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Contact Form 7 Round Robin Lead Distribution versions 1.2.1 and earlier
Description The issue is related to improper neutralization of special elements used in an SQL command, allowing SQL injection. This can be exploited through the NotFound Contact Form 7 Round Robin Lead Distribution plugin.
Recommendations For versions 1.2.1 and earlier, update to a version that contains a fix for this issue, as no specific workaround is provided for these versions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-23784

Affected Products

Contact Form 7 Round Robin Lead Distribution