Record summary

CVE-2018-25346 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress database.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 1.12.24affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Form Maker 1.12.24 - SQL InjectionExploitDB exploitby defensecodeNot analyzed1 file
ExploitDB

PoC details

References

3