Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45167 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3. |
Tue, 28 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in aiyaz Khorajia Contact form 7 Custom validation cf7-field-validation.This issue affects Contact form 7 Custom validation: from n/a through <= 1.1.3. | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3. |
| Title | WordPress Contact form 7 Custom validation plugin <= 1.1.3 - Unauth. SQL Injection (SQLi) vulnerability | WordPress Contact form 7 Custom validation Plugin <= 1.1.3 is vulnerable to SQL Injection |
Tue, 28 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3. | A vulnerability in aiyaz Khorajia Contact form 7 Custom validation cf7-field-validation.This issue affects Contact form 7 Custom validation: from n/a through <= 1.1.3. |
| Title | WordPress Contact form 7 Custom validation Plugin <= 1.1.3 is vulnerable to SQL Injection | WordPress Contact form 7 Custom validation plugin <= 1.1.3 - Unauth. SQL Injection (SQLi) vulnerability |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:08:36.942Z
Reserved: 2023-08-17T10:47:42.478Z
Link: CVE-2023-40609
Updated: 2024-08-02T18:38:50.334Z
Status : Modified
Published: 2023-11-06T09:15:08.307
Modified: 2026-04-28T19:21:12.317
Link: CVE-2023-40609
No data.
OpenCVE Enrichment
No data.
EUVD