Lucene search

K
wpvulndbWpvulndbWPVDB-ID:1FBC305D-5E3A-4749-B5A6-82DD5D4EBF6A
HistoryNov 16, 2023 - 12:00 a.m.

Contact form 7 Custom validation <= 1.1.3 - Unauthenticated SQLi

2023-11-1600:00:00
wpscan.com
12
contact form 7
custom validation
sql injection
unauthenticated users
security vulnerability

AI Score

8

Confidence

Low

EPSS

0.001

Percentile

33.0%

Description The plugin does not properly sanitise and escape the post parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated uers

AI Score

8

Confidence

Low

EPSS

0.001

Percentile

33.0%

Related for WPVDB-ID:1FBC305D-5E3A-4749-B5A6-82DD5D4EBF6A