← Back to search

CVE-2026-14872

6.8 MEDIUM

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
The flaw allows SQL injection due to improper parameter sanitization in certain WordPress plugins, enabling administrators or users with specific capabilities to execute arbitrary database commands.
Exploitability
Exploitation requires user access and specific plugin versions; difficulty varies based on network security and user privileges.
Blast radius
If exploited, it could lead to data theft or corruption affecting the website’s backend databases.
Prioritized remediation
Update affected plugins to version 1.5.5 or later immediately.
sql-injectionwordpresssanitizationsecurity-update

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Weaknesses

CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.