CVE-2025-46252
גבוהה 7.2
תיאור (מקור, אנגלית)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-20/9/2026
- CWE
- CWE-89
מוצרים מושפעים
kofimokome: message filter for contact form 7
קישורים
- https://patchstack.com/database/wordpress/plugin/cf7-message-filter/vulnerabil… Third Party Advisory