CVE-2017-20244

HIGH

Wow Forms WordPress Plugin 2.1 SQL Injection

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-20244. PoCs published by TAD GROUP.

AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in the Wow Forms WordPress plugin (v2.1) via the 'mwpformid' POST parameter. It includes a sqlmap command to exploit the vulnerability, showing payloads for boolean-based blind, time-based blind, and UNION-based SQL injection.

Description

Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the 'send_mwp_form' action to extract sensitive database contents.

Exploits (1)

exploitdb WORKING POC
by TAD GROUP · textwebappsphp
https://www.exploit-db.com/exploits/41922

The exploit demonstrates a SQL injection vulnerability in the Wow Forms WordPress plugin (v2.1) via the 'mwpformid' POST parameter. It includes a sqlmap command to exploit the vulnerability, showing payloads for boolean-based blind, time-based blind, and UNION-based SQL injection.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Wow Forms WordPress Plugin v2.1
No auth needed
Prerequisites: Access to the target WordPress admin-ajax.php endpoint
devstral-2 · analyzed Jun 09, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit exploit
ExploitDB-41922
https://www.exploit-db.com/exploits/41922
Product product
Official Product Homepage
http://wow-company.com/
Product product
Official Product Homepage
https://tad.group
Product product
Product Reference
https://wordpress.org/plugins/mwp-forms/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Wow Forms WordPress Plugin 2.1 SQL Injection
https://www.vulncheck.com/advisories/wow-forms-wordpress-plugin-sql-injection

Scores

CVSS v3 8.2
EPSS 0.0027
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Wow-Company/Wow Forms 2.1
Published Jun 09, 2026
Tracked Since Jun 09, 2026