CVE-2015-9452: SQL Injection
Published Oct 7, 2019
·Updated
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nexformsId parameter.
Affected Software
2 affected components
Nex-forms - Ultimate Form Builder Project Nex-forms - Ultimate Form Builder Wordpress<4.6.1
Basixonline Nex-forms Wordpress<4.6.1
Event History
Oct 7, 2019
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9452?
CVE-2015-9452 is considered a high severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2015-9452?
To fix CVE-2015-9452, update the Nex-Forms ultimate form builder plugin to version 4.6.1 or later.
3
What does CVE-2015-9452 affect?
CVE-2015-9452 affects the Nex-Forms Express WP Form Builder plugin versions prior to 4.6.1 for WordPress.
4
What type of vulnerability is CVE-2015-9452?
CVE-2015-9452 is an SQL injection vulnerability that can allow attackers to execute arbitrary SQL queries.
5
How can I check if my site is vulnerable to CVE-2015-9452?
You can check if your site is vulnerable to CVE-2015-9452 by verifying the installed version of the Nex-Forms Express WP Form Builder plugin on your WordPress site.