VYPR
High severity8.5NVD Advisory· Published Jul 4, 2025· Updated Apr 23, 2026

CVE-2025-28967

CVE-2025-28967

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LITE contact-us-page-contact-people allows SQL Injection.This issue affects Contact Us page - Contact people LITE: from n/a through <= 3.7.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A SQL Injection vulnerability in the Contact Us page – Contact people LITE plugin (≤3.7.4) allows unauthenticated database manipulation.

Vulnerability

Overview

CVE-2025-28967 is a SQL Injection vulnerability discovered in the WordPress plugin "Contact Us page – Contact people LITE," affecting all versions up to and including 3.7.4. The flaw stems from improper neutralization of special elements used in an SQL command, allowing an attacker to inject arbitrary SQL statements into backend queries [1].

Exploitation

The vulnerability can be exploited without authentication, making it accessible to any remote attacker. By sending crafted input to the plugin’s contact form or other user-facing fields, the attacker can bypass the intended filtering and execute malicious SQL commands against the underlying database [1].

Impact

Successful exploitation could lead to unauthorized access, extraction, or manipulation of sensitive data stored in the WordPress database, such as user credentials, personal information, or site configuration. Given the severity (CVSS 8.5), this represents a critical risk to site integrity and confidentiality [1].

Mitigation

The vendor has released a patched version (3.7.5 or later) to address the issue. Site administrators are strongly advised to update the plugin immediately. If updating is not possible, contacting the hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.