CVE-2025-31424

CRITICAL

WP Lead Capturing Pages <2.3 - SQL Injection

Title source: llm
STIX 2.1

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through < 2.6.

Scores

CVSS v3 9.3
EPSS 0.0037
EPSS Percentile 29.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
kamleshyadav/WP Lead Capturing Pages < 2.3
kamleshyadav/WP Lead Capturing Pages < 2.6
Published Jun 09, 2025
Tracked Since Feb 18, 2026