PT-2023-15409 · Unknown · Themefic Ultimate Addons For Contact Form 7

Minhtuanact

·

Published

2023-06-19

·

Updated

2023-06-27

·

CVE-2022-47586

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Themefic Ultimate Addons for Contact Form 7 plugin versions prior to 3.1.24
Description The issue is related to an Unauth. SQL Injection (SQLi) vulnerability. This means that an attacker could potentially inject malicious SQL code into the database without proper authorization, leading to unauthorized access or modification of data.
Recommendations For Themefic Ultimate Addons for Contact Form 7 plugin versions prior to 3.1.24, update to version 3.1.24 or later to resolve the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-47586

Affected Products

Themefic Ultimate Addons For Contact Form 7