PT-2022-20737 · WordPress · Nex-Forms

Elias Hohl

·

Published

2022-09-19

·

Updated

2023-03-27

·

CVE-2022-3142

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NEX-Forms WordPress plugin versions prior to 7.9.7
Description The issue arises from the plugin's failure to properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. This can be exploited by anyone permitted to view the forms statistics chart, which by default includes administrators, although permissions can be configured otherwise via the plugin settings.
Recommendations For versions prior to 7.9.7, update to version 7.9.7 or later to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3142

Affected Products

Nex-Forms