WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'name' and 'search_labels' parameters to extract sensitive database information or escalate privileges.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 23 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'name' and 'search_labels' parameters to extract sensitive database information or escalate privileges. | |
| Title | WordPress Contact Form Maker Plugin 1.12.20 SQL Injection | |
| First Time appeared |
Web-dorado
Web-dorado contact Form Maker |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:web-dorado:contact_form_maker:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Web-dorado
Web-dorado contact Form Maker |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-23T18:30:48.903Z
Reserved: 2026-05-23T15:26:41.278Z
Link: CVE-2018-25347
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses