What the vulnerability does
01Description
Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L
What the vulnerability does
Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.
Explanation of Vulnerability in Simple Terms
Ultimate Addons for Contact Form 7 versions up to 3.1.23 contain a SQL injection vulnerability in database queries. An attacker can craft a malicious link that, when clicked by a site visitor, executes arbitrary SQL commands. This can expose sensitive data from the WordPress database. The vulnerability requires user interaction and affects the site's confidentiality and availability.
What an attacker can do
Execute SQL commands to read or modify database contents, including user data and site configuration.
Potential impact on your site
Visitor data, user credentials, and other database contents can be exposed or corrupted without your knowledge.
Conditions required to exploit
Attacker must trick a site visitor into clicking a malicious link (user interaction required). No authentication needed.
Key dates
External resources
Related vulnerabilities