LiveActive security incident?Get immediate response
CVE Record

CVE-2018-25352: WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id

WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the ufbl_get_entry_detail_action action to extract, modify, or escalate privileges within the WordPress database.

HighCVSS 7.1Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A WordPress plugin called Ultimate Form Builder Lite (version 1.3.7 and earlier) has a flaw that lets a logged-in user trick the site's database into running unintended commands. That can expose form submissions, alter records, or help an attacker gain more access inside the WordPress admin.

Executive priority

Treat as high priority for any environment running this plugin. The bug is publicly documented with a working PoC and enables data theft or privilege escalation on WordPress sites hosting customer form submissions. Immediate action: confirm plugin presence, remove or disable if a patch is not identified, and preserve logs for review.

Technical view

SQL injection (CWE-89) in the ufbl_get_entry_detail_action handler exposed through admin-ajax.php. The entry_id POST parameter is passed into a database query without safe parameterization, so an authenticated attacker can inject SQL to read or modify data. CVSS 4.0 base score 7.1; requires low privileges and network access, no user interaction.

Likely exposure

Any WordPress site running Ultimate Form Builder Lite 1.3.7 or older where an attacker can obtain any authenticated account (including subscriber-level in many WordPress deployments) is exposed. Sites that allow open registration or share credentials with untrusted users face the highest risk. Sources do not name a fixed version, so all listed versions should be treated as vulnerable pending vendor guidance.

Exploitation context

Not listed in CISA KEV. A public proof-of-concept exists on Exploit-DB (entry 44884) and the issue is documented in a VulnCheck advisory, indicating exploitation techniques are publicly known. No sources cited here confirm active in-the-wild exploitation campaigns, but the low complexity and public PoC make opportunistic abuse plausible.

Researcher notes

Vulnerable sink is the ufbl_get_entry_detail_action AJAX handler; entry_id POST parameter reaches a query without parameterization. Authentication is required (PR:L), so exploitation depends on obtaining any WordPress account. The "Vulnerability Advisory" reference URL in the bundle is a placeholder (vulnerablesite.com) and should not be treated as an authoritative source. No fixed version, CPE, or vendor patch is named in the provided sources; verify current plugin status on WordPress.org before drawing conclusions about remediation availability.

Mitigation direction

  • Inventory WordPress sites for Ultimate Form Builder Lite and identify the installed version.
  • Check the plugin's WordPress.org page and vendor channels for a patched release or removal guidance.
  • If no patched version is confirmed, disable or remove the plugin until vendor guidance is available.
  • Restrict WordPress account registration and audit low-privilege user accounts.
  • Place a WAF rule in front of admin-ajax.php to inspect ufbl_get_entry_detail_action requests.
  • Rotate database and admin credentials if exploitation is suspected.

Validation and detection

  • Enumerate plugin versions via wp-cli or the WordPress admin Plugins screen.
  • Review web server and admin-ajax.php logs for POST requests using the ufbl_get_entry_detail_action action.
  • Search database and error logs for anomalous SQL syntax errors tied to entry_id values.
  • Audit wp_users for unexpected role escalations or newly created administrator accounts.
  • Run an authenticated vulnerability scan against affected sites to confirm the injection path is closed.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-89: Database access and collection lookup

Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2018-25352 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.1 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.1CVSS 4.0HighCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:NVulnCheck
7.1CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N2.84.2VulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

7.1High
CVSS 4.0 vector shape for CVE-2018-25352Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
ultimate-form-builder-liteUltimate Form Builder Lite0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.