CVE-2018-25347: Web-Dorado Contact Form Maker

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'name' and 'search_labels' parameters to extract sensitive database information or escalate privileges.

Affected products

  • Web-Dorado Contact Form Maker: up to and including 1.12.20

Published 2026-05-23. Last modified 2026-07-23.