CVE-2025-68590
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68590 is a Blind SQL Injection vulnerability in the CRM Perks "Integration for Contact Form 7 HubSpot" WordPress plugin (slug: cf7-hubspot). It affects all versions of the plugin up to and including 1.4.2, and was published on December 24, 2025, with Patchstack as the assigning authority (Red Hat CVE, Feedly). The vulnerability carries a CVSS v3.1 base score of 7.6 (High), with a changed scope reflecting potential impact beyond the vulnerable component (Feedly).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is incorporated into database queries without adequate sanitization or parameterization (Feedly). The attack vector is network-based with low attack complexity, but exploitation requires high privileges (e.g., an authenticated administrator role), and no user interaction is needed. The blind SQL injection variant means the attacker infers database contents through boolean-based or time-based response differences rather than direct output, making it stealthier but still highly effective for data extraction (Feedly). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an attacker with high-privilege access to manipulate backend database queries, potentially reading, modifying, or deleting sensitive data stored in the WordPress database — including user credentials, form submissions, and HubSpot integration tokens (Feedly). The CVSS scope is marked as "Changed," indicating that exploitation could affect resources beyond the plugin itself, such as the broader WordPress database or connected HubSpot account data. Availability is also marginally impacted (rated Low), suggesting potential for disruption to database operations.

Exploitability

There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.031% (0.000310), indicating a low near-term probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

The primary remediation is to update the "Integration for Contact Form 7 HubSpot" plugin to a version newer than 1.4.2 (Feedly). As interim measures, administrators should implement a Web Application Firewall (WAF) with rules to detect and block SQL injection patterns, enforce least-privilege database account permissions, and audit database access logs for anomalous query patterns. Input validation and the use of parameterized queries (prepared statements) at the code level are recommended best practices to prevent recurrence.

Community reactions

The vulnerability received brief social media coverage shortly after disclosure, with mentions on Mastodon (infosec.exchange and mastodon.social via TheHackerWire) and Bluesky (Feedly). It was also included in a Red Packet Security weekly CISA vulnerability summary for the week of December 22, 2025. No significant vendor statements or in-depth researcher commentary have been published beyond the initial Patchstack disclosure.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14444HIGH7.5
  • wp-fusion
NoYesSep 07, 2026
CVE-2026-6431HIGH7.2
  • profile-builder
NoYesSep 07, 2026
CVE-2026-12757MEDIUM6.5
  • email-subscribers
NoYesSep 07, 2026
CVE-2026-8279MEDIUM5.3
  • learning-management-system
NoYesSep 07, 2026
CVE-2026-4945MEDIUM5.3
  • otter-blocks
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management