Junglewise Threat Intelligence

CVE-2026-42742: Aman Views for WPForms Blind SQL Injection

CVE-2026-42742 · Severity: high · CVSS 8.5 · Published 2026-05-12

Executive brief

A security vulnerability exists in the Views for WPForms plugin, which is used to display form submission data on WordPress websites. An attacker with basic user permissions could exploit this flaw to extract sensitive information from the website's database. This could lead to the exposure of private customer data or administrative information, potentially compromising the entire site.

Technical details

The Aman Views for WPForms (views-for-wpforms-lite) plugin for WordPress is vulnerable to Blind SQL Injection due to improper neutralization of special elements used in an SQL command. The vulnerability exists in versions up to and including 3.4.6. An attacker with low-level privileges (Subscriber or higher) can send specially crafted network requests to trigger the injection. Because it is a blind injection, the attacker can infer data from the database by observing differences in server responses or timing. This can lead to unauthorized access to sensitive data, including user credentials or site configuration details. Users are advised to update to a version higher than 3.4.6 if available.

Affected products

  • Aman Views for WPForms (views-for-wpforms-lite) <= 3.4.6

Timeline

  • 2026-05-12: advisory: Advisory published by NVD and Patchstack

References