CVE-2025-31424 PUBLISHED

WordPress WP Lead Capturing Pages plugin <= 2.3 - SQL Injection vulnerability

Assigner: Patchstack
Reserved: 28.03.2025 Published: 09.06.2025 Updated: 09.06.2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages allows Blind SQL Injection. This issue affects WP Lead Capturing Pages: from n/a through 2.3.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
CVSS Score: 9.3

Product Status

Vendor kamleshyadav
Product WP Lead Capturing Pages
Versions Default: unaffected
  • affected from n/a to 2.3 (incl.)

Credits

  • Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance) finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-7 Blind SQL Injection