vendor:
WordPress Form Maker Plugin
by:
Neven Biruski
N/A
CVSS
HIGH
SQL Injection
89
CWE
Product Name: WordPress Form Maker Plugin
Affected Version From: 1.12.24
Affected Version To: 1.12.24 and below
Patch Exists: YES
Related CWE:
CPE: a:wordpress:form_maker
Platforms Tested:
2018
WordPress Form Maker Plugin 1.12.24 – SQL Injection
The SQL injection vulnerabilities in WordPress Form Maker Plugin 1.12.24 and below allow unauthorized users to escalate their privileges or access and modify database contents. The vulnerabilities can be exploited by submitting specially crafted forms with malicious SQL statements.
Mitigation:
Update the WordPress Form Maker plugin to the latest version.