CVE-2025-54678

9.3

WhiteStudio · Easy Form Builder

A blind SQL injection vulnerability in the Easy Form Builder WordPress plugin allows unauthenticated attackers to extract sensitive database information.

Executive summary

A critical blind SQL injection vulnerability in the Easy Form Builder WordPress plugin allows unauthenticated attackers to compromise database confidentiality.

Vulnerability

This is an Improper Neutralization of Special Elements used in an SQL Command (CWE-89) vulnerability. It permits an unauthenticated attacker to execute blind SQL injection attacks against the WordPress database via the plugin.

Business impact

With a CVSS score of 9.3, this vulnerability poses a severe threat to data privacy. Successful exploitation allows for the exfiltration of sensitive information stored within the database, which could lead to significant regulatory and reputational consequences for the organization.

Remediation

Immediate Action: Update the Easy Form Builder plugin to version 3.8.16 or later to patch the vulnerability.

Proactive Monitoring: Monitor for unusual database traffic or errors that could indicate an attacker attempting to perform blind SQL injection enumeration.

Compensating Controls: Use a Web Application Firewall (WAF) to inspect and block malicious SQL syntax within incoming HTTP requests.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability allows for unauthenticated access to database contents, necessitating urgent attention. Administrators must ensure all instances of the Easy Form Builder plugin are updated to version 3.8.16 to mitigate the risk of data compromise.