PT-2023-25376 · WordPress · Contact Form Generator

Emili Castells

·

Published

2023-11-06

·

Updated

2023-11-10

·

CVE-2023-35911

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contact Form Generator : Creative form builder for WordPress versions prior to 2.6.0
Description The issue is related to an SQL Injection vulnerability due to the improper neutralization of special elements used in an SQL command. This allows for SQL Injection attacks.
Recommendations For versions prior to 2.6.0, update to version 2.6.0 or later to resolve the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-35911

Affected Products

Contact Form Generator