CVE-2025-8420
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-06

Last updated on: 2026-04-08

Assigner: Wordfence

Description
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-06
Last Modified
2026-04-08
Generated
2026-05-07
AI Q&A
2025-08-06
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
wordpress request_a_quote *
wordpress request_a_quote 2.5.3
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The vulnerability exists in the Request a Quote Form plugin for WordPress, versions up to 2.5.2. It is a Remote Code Execution (RCE) flaw caused by improper validation of user input in the emd_form_builder_lite_pagenum function. This allows unauthenticated attackers to execute code on the server by using user input as a function name, although they cannot pass parameters to these functions.


How can this vulnerability impact me? :

This vulnerability can allow unauthenticated attackers to execute arbitrary code on the affected server, potentially leading to full compromise of the server, data theft, data loss, or disruption of services. Because the attacker can run code remotely, it poses a high risk to the confidentiality, integrity, and availability of the system.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart