PT-2023-17120 · WordPress · Ultimate Addons For Contact Form 7

Etan Imanol Castro Aldrete

·

Published

2023-06-09

·

Updated

2023-06-16

·

CVE-2023-1615

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Ultimate Addons for Contact Form 7 plugin for WordPress versions up to and including 3.1.23
Description The issue allows authenticated attackers of any authorization level to perform SQL Injection via the id parameter. This enables them to append additional SQL queries into existing ones, potentially extracting sensitive information from the database.
Recommendations For versions up to and including 3.1.23, update to a version higher than 3.1.23 to resolve the issue. As a temporary workaround, consider restricting access to the id parameter in affected API endpoints until a patch is available.

Fix

Related Identifiers

CVE-2023-1615

Affected Products

Ultimate Addons For Contact Form 7