Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kofimokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.
History

Wed, 30 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Kofimokome
Kofimokome message Filter For Contact Form 7
CPEs cpe:2.3:a:kofimokome:message_filter_for_contact_form_7:*:*:*:*:*:wordpress:*:*
Vendors & Products Kofimokome
Kofimokome message Filter For Contact Form 7

Tue, 22 Apr 2025 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kofimokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.
Title WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2025-04-22T09:53:34.550Z

Updated: 2025-04-22T13:39:23.124Z

Reserved: 2025-04-22T09:21:43.075Z

Link: CVE-2025-46252

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-04-22T10:15:19.970

Modified: 2025-04-30T15:10:04.440

Link: CVE-2025-46252

cve-icon Redhat

No data.