PT-2024-3155 · WordPress · Forminator
Published
2024-04-12
·
Updated
2025-04-04
·
CVE-2024-31077
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Forminator versions prior to 1.29.3
Description
The issue is related to a SQL injection vulnerability due to a lack of protection measures for the SQL query structure. This vulnerability can be exploited by a remote attacker to modify arbitrary data and cause a denial-of-service condition. A remote authenticated attacker with administrative privileges may obtain and alter any information in the database.
Recommendations
For versions prior to 1.29.3, upgrade the plugin to the latest version immediately.
As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation.
Audit your site for any signs of compromise after applying the update.
Fix
DoS
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forminator