First published: Tue Apr 22 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kofimokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Message Filter for Contact Form 7 | <=1.6.3.2 | |
WordPress Message Filter for Contact Form 7 | <=1.6.3.2 | |
Kofi Mokome Message Filter for Contact Form 7 | <1.6.3.3 |
Update the WordPress Message Filter for Contact Form 7 plugin to the latest available version (at least 1.6.33).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46252 is classified as a critical severity vulnerability due to its potential for SQL injection.
To fix CVE-2025-46252, update Message Filter for Contact Form 7 to the latest version beyond 1.6.3.2.
CVE-2025-46252 affects all versions of Message Filter for Contact Form 7 up to and including 1.6.3.2.
CVE-2025-46252 can be exploited through SQL injection attacks, allowing attackers to execute arbitrary SQL queries.
Currently, the best workaround for CVE-2025-46252 is to disable the Message Filter for Contact Form 7 until it can be updated.