vendor:
Calculated Fields Form
by:
Ibrahim Raafat
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Calculated Fields Form
Affected Version From: 1.0.10
Affected Version To: 1.0.11
Patch Exists: YES
Related CWE: N/A
CPE: a:softdiscover:calculated_fields_form
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2015
Calculated Fields Form WordPress Plugin <= 1.0.10 - Remote SQL Injection Vulnerability
There are sql injection vulnerabilities in Calculated Fields Form Plugin which could allow the attacker to execute sql queries into database. These queries are execute without any csrf protection, The attacker can use this csrf vulnerability to execute queries in the sql by sending malicious page to the logged in admin. Attacker can use this vulnerabilities to update admin password.
Mitigation:
Upgrade the plugin to version 1.0.12 or higher.