CVE-2024-3495Active Exploitation

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-06: 1Active Exploitation · 2026-02-06: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-06: 102-06
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2024-3495 : CRITICAL WORDPRESS SQL INJECTION ALERT 🚨 An unauthenticated SQL injection vulnerability has been disclosed in the Country State City Dropdown CF7 WordPress plugin, exploitable via exposed AJAX endpoints and requiring no authentication or user interaction. Risk Severity: - Critical (CVSS 9.8, active exploitation, public exploits available, trending) Impact: - Unauthenticated SQL injection - Complete WordPress database compromise - Administrator credential theft - Authentication bypass & site takeover - Potential remote code execution via webshell deployment - Ransomware and data destruction scenarios Root Cause: - CWE-89 (Improper Neutralization of Special Elements in SQL Commands). The plugin directly concatenates user-supplied `cnt` (country) and `sid` (state) parameters into SQL queries within its AJAX handlers without using prepared statements or proper input sanitization. Attackers can: - Send crafted requests to `admin-ajax.php` endpoints without authentication - Inject arbitrary SQL via location dropdown parameters - Exfiltrate sensitive data including `wp_users` credentials and site secrets - Modify database content or plant persistent backdoors Are You Affected? - Vulnerable: Country State City Dropdown CF7 versions ≤ 2.7.2 - Scope: Internet-facing WordPress sites using Contact Form 7 with this plugin enabled Immediate Action Required: - Update: Upgrade to version 2.7.3 or later immediately - Mitigation: Disable and remove the plugin if patching cannot be completed at once - Audit: Monitor `admin-ajax.php` for suspicious `cscf7_get_*` requests and review database logs for injection artifacts This vulnerability is being actively scanned and exploited at scale. Unpatched WordPress sites should be assumed exposed. 🛡️ #ostorlabCVE

    Post summary

    CVE-2024-3495 is a critical unauthenticated WordPress SQL injection affecting the Country State City Dropdown CF7 plugin. The vulnerability is actively exploited in the wild, public exploits exist, and a patch (v2.7.3) is available.

    0000191
    582 followersView on X

Explore more