PT-2026-47767 · Undefined · Undefined

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2017-20244

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the 'send mwp form' action to extract sensitive database contents.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2017-20244

Affected Products

Undefined