{"id":"CVE-2026-14872","published":"2026-08-04T07:16:28.923","lastModified":"2026-08-04T18:16:43.910","description":"The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.","cvssScore":6.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/557414c2-70b9-4466-8727-d8a2c9a8a502/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows SQL injection due to improper parameter sanitization in certain WordPress plugins, enabling administrators or users with specific capabilities to execute arbitrary database commands.","exploitability":"Exploitation requires user access and specific plugin versions; difficulty varies based on network security and user privileges.","blast_radius":"If exploited, it could lead to data theft or corruption affecting the website’s backend databases.","remediation":"Update affected plugins to version 1.5.5 or later immediately.","tags":["sql-injection","wordpress","sanitization","security-update"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:04:05.444Z"}}