
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68590 is a Blind SQL Injection vulnerability in the CRM Perks "Integration for Contact Form 7 HubSpot" WordPress plugin (slug: cf7-hubspot). It affects all versions of the plugin up to and including 1.4.2, and was published on December 24, 2025, with Patchstack as the assigning authority (Red Hat CVE, Feedly). The vulnerability carries a CVSS v3.1 base score of 7.6 (High), with a changed scope reflecting potential impact beyond the vulnerable component (Feedly).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is incorporated into database queries without adequate sanitization or parameterization (Feedly). The attack vector is network-based with low attack complexity, but exploitation requires high privileges (e.g., an authenticated administrator role), and no user interaction is needed. The blind SQL injection variant means the attacker infers database contents through boolean-based or time-based response differences rather than direct output, making it stealthier but still highly effective for data extraction (Feedly). No public proof-of-concept code has been identified at this time.
Successful exploitation allows an attacker with high-privilege access to manipulate backend database queries, potentially reading, modifying, or deleting sensitive data stored in the WordPress database — including user credentials, form submissions, and HubSpot integration tokens (Feedly). The CVSS scope is marked as "Changed," indicating that exploitation could affect resources beyond the plugin itself, such as the broader WordPress database or connected HubSpot account data. Availability is also marginally impacted (rated Low), suggesting potential for disruption to database operations.
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.031% (0.000310), indicating a low near-term probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
The primary remediation is to update the "Integration for Contact Form 7 HubSpot" plugin to a version newer than 1.4.2 (Feedly). As interim measures, administrators should implement a Web Application Firewall (WAF) with rules to detect and block SQL injection patterns, enforce least-privilege database account permissions, and audit database access logs for anomalous query patterns. Input validation and the use of parameterized queries (prepared statements) at the code level are recommended best practices to prevent recurrence.
The vulnerability received brief social media coverage shortly after disclosure, with mentions on Mastodon (infosec.exchange and mastodon.social via TheHackerWire) and Bluesky (Feedly). It was also included in a Red Packet Security weekly CISA vulnerability summary for the week of December 22, 2025. No significant vendor statements or in-depth researcher commentary have been published beyond the initial Patchstack disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."