CVE-2025-28967
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LITE contact-us-page-contact-people allows SQL Injection.This issue affects Contact Us page - Contact people LITE: from n/a through <= 3.7.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A SQL Injection vulnerability in the Contact Us page – Contact people LITE plugin (≤3.7.4) allows unauthenticated database manipulation.
Vulnerability
Overview
CVE-2025-28967 is a SQL Injection vulnerability discovered in the WordPress plugin "Contact Us page – Contact people LITE," affecting all versions up to and including 3.7.4. The flaw stems from improper neutralization of special elements used in an SQL command, allowing an attacker to inject arbitrary SQL statements into backend queries [1].
Exploitation
The vulnerability can be exploited without authentication, making it accessible to any remote attacker. By sending crafted input to the plugin’s contact form or other user-facing fields, the attacker can bypass the intended filtering and execute malicious SQL commands against the underlying database [1].
Impact
Successful exploitation could lead to unauthorized access, extraction, or manipulation of sensitive data stored in the WordPress database, such as user credentials, personal information, or site configuration. Given the severity (CVSS 8.5), this represents a critical risk to site integrity and confidentiality [1].
Mitigation
The vendor has released a patched version (3.7.5 or later) to address the issue. Site administrators are strongly advised to update the plugin immediately. If updating is not possible, contacting the hosting provider or web developer for assistance is recommended [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=3.7.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.