CVE-2025-23784
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Jan 22, 2025
CWE ID 89
Summary
CVE-2025-23784 is an SQL injection vulnerability affecting Contact Form 7 Round Robin Lead Distribution, with versions from n/a to 1.2.1 being impacted. An attacker can exploit this flaw by injecting malicious SQL code through special elements in the contact form, potentially gaining unauthorized access to sensitive data or taking control of the affected system. This issue occurs due to improper neutralization of such elements, allowing SQL commands to bypass intended security restrictions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.