WordPress Contact Form Maker SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the WordPress Contact Form Maker plugin, specifically in version 1.12.20 and prior. This vulnerability allows authenticated attackers to manipulate database queries by injecting malicious SQL code through the 'name' and 'search_labels' parameters. The exploitation of this vulnerability could lead to the extraction of sensitive database information or unauthorized privilege escalation.

Impact

Exploitation of this vulnerability could result in unauthorized database access, allowing attackers to extract, modify, or delete database information. Additionally, the vulnerability could be used to escalate privileges within the application.

Reproduction

To reproduce this vulnerability, log in to a WordPress site as an authenticated user with access to the Contact Form Maker plugin settings. Then, send a POST request to 'wp-admin/admin-ajax.php' with the 'action' parameter set to 'FormMakerSQLMapping_fmc' or 'generete_csv_fmc'. Include the 'name' or 'search_labels' parameters with crafted SQL payloads that exploit the SQL injection vulnerability. The injected SQL code can be designed to, for example, extract data from the database using SQL injection techniques such as time-based blind injection.

Added: May 26, 2026, 9:17 PM
Updated: May 26, 2026, 9:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
9.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.