PT-2021-16144 · WordPress · Wow Forms

Shreya Pohekar

·

Published

2021-11-08

·

Updated

2021-11-10

·

CVE-2021-24628

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wow Forms WordPress plugin versions prior to 3.1.4
Description The issue arises from the lack of sanitization or escaping of the did GET parameter, which is used in a SQL statement when deleting a form in the admin dashboard. This leads to an authenticated SQL injection.
Recommendations For Wow Forms WordPress plugin versions prior to 3.1.4, update to version 3.1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the admin dashboard to minimize the risk of exploitation. Avoid using the did parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24628

Affected Products

Wow Forms