nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25346 CVE-2018-25346
HIGH
WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php
Record summary
CVE-2018-25346 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress database.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Form MakerBrowse 10Web / Form Maker | CVE List | Through 1.12.24 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Form Maker 1.12.24 - SQL InjectionExploitDB exploitby defensecodeNot analyzed1 file
References
3ExploitDB-44853exploit
https://www.exploit-db.com/exploits/44853 VulnCheck Advisory: WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.phpThird-party advisory
https://www.vulncheck.com/advisories/wordpress-form-maker-plugin-sql-injection-via-admin-ajax-php