Executive brief
A security vulnerability exists in the Persian Gravity Forms plugin for WordPress, which provides localized form-building capabilities. An attacker with administrative privileges could exploit this flaw to interact directly with the website's database. This could lead to the unauthorized extraction of sensitive information or disruption of site operations.
Technical details
The Hannan Persian Gravity Forms (گرویتی فرم فارسی) plugin for WordPress is vulnerable to Blind SQL Injection due to improper neutralization of special elements used in SQL commands. The vulnerability exists in versions up to and including 3.0.2. An attacker with high-level privileges (such as an Administrator) can exploit this flaw via network requests to execute arbitrary SQL queries against the backend database. This could allow for the exfiltration of sensitive data or minor service disruption. The issue is addressed in version 3.0.3.
Affected products
- Hannan گرویتی فرم فارسی (Persian Gravity Forms) <= 3.0.2
Timeline
- 2026-06-10: other: Reported by researcher Ananda Dhakal
- 2026-07-12: patched: Patch released in version 3.0.3
- 2026-07-13: disclosed: CVE published