CVE-2018-25352: WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id
WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the ufbl_get_entry_detail_action action to extract, modify, or escalate privileges within the WordPress database.
Security readout for executives and security teams
Plain-English summary
A WordPress plugin called Ultimate Form Builder Lite (version 1.3.7 and earlier) has a flaw that lets a logged-in user trick the site's database into running unintended commands. That can expose form submissions, alter records, or help an attacker gain more access inside the WordPress admin.
Executive priority
Treat as high priority for any environment running this plugin. The bug is publicly documented with a working PoC and enables data theft or privilege escalation on WordPress sites hosting customer form submissions. Immediate action: confirm plugin presence, remove or disable if a patch is not identified, and preserve logs for review.
Technical view
SQL injection (CWE-89) in the ufbl_get_entry_detail_action handler exposed through admin-ajax.php. The entry_id POST parameter is passed into a database query without safe parameterization, so an authenticated attacker can inject SQL to read or modify data. CVSS 4.0 base score 7.1; requires low privileges and network access, no user interaction.
Likely exposure
Any WordPress site running Ultimate Form Builder Lite 1.3.7 or older where an attacker can obtain any authenticated account (including subscriber-level in many WordPress deployments) is exposed. Sites that allow open registration or share credentials with untrusted users face the highest risk. Sources do not name a fixed version, so all listed versions should be treated as vulnerable pending vendor guidance.
Exploitation context
Not listed in CISA KEV. A public proof-of-concept exists on Exploit-DB (entry 44884) and the issue is documented in a VulnCheck advisory, indicating exploitation techniques are publicly known. No sources cited here confirm active in-the-wild exploitation campaigns, but the low complexity and public PoC make opportunistic abuse plausible.
Researcher notes
Vulnerable sink is the ufbl_get_entry_detail_action AJAX handler; entry_id POST parameter reaches a query without parameterization. Authentication is required (PR:L), so exploitation depends on obtaining any WordPress account. The "Vulnerability Advisory" reference URL in the bundle is a placeholder (vulnerablesite.com) and should not be treated as an authoritative source. No fixed version, CPE, or vendor patch is named in the provided sources; verify current plugin status on WordPress.org before drawing conclusions about remediation availability.
Mitigation direction
Inventory WordPress sites for Ultimate Form Builder Lite and identify the installed version.
Check the plugin's WordPress.org page and vendor channels for a patched release or removal guidance.
If no patched version is confirmed, disable or remove the plugin until vendor guidance is available.
Restrict WordPress account registration and audit low-privilege user accounts.
Place a WAF rule in front of admin-ajax.php to inspect ufbl_get_entry_detail_action requests.
Rotate database and admin credentials if exploitation is suspected.
Validation and detection
Enumerate plugin versions via wp-cli or the WordPress admin Plugins screen.
Review web server and admin-ajax.php logs for POST requests using the ufbl_get_entry_detail_action action.
Search database and error logs for anomalous SQL syntax errors tied to entry_id values.
Audit wp_users for unexpected role escalations or newly created administrator accounts.
Run an authenticated vulnerability scan against affected sites to confirm the injection path is closed.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-89: Database access and collection lookup
Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.