First published: Mon Oct 07 2019(Updated: )
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Basix NEX-Forms – Ultimate Form Builder | <4.6.1 | |
Basix NEX-Forms – Ultimate Form Builder | <4.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9452 is considered a high severity vulnerability due to the potential for SQL injection attacks.
To fix CVE-2015-9452, update the Nex-Forms ultimate form builder plugin to version 4.6.1 or later.
CVE-2015-9452 affects the Nex-Forms Express WP Form Builder plugin versions prior to 4.6.1 for WordPress.
CVE-2015-9452 is an SQL injection vulnerability that can allow attackers to execute arbitrary SQL queries.
You can check if your site is vulnerable to CVE-2015-9452 by verifying the installed version of the Nex-Forms Express WP Form Builder plugin on your WordPress site.