CVE-2017-15919: SQL Injection
Published Oct 26, 2017
·Updated
The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.
Affected Software
1 affected component
Accesspressthemes Ultimate-form-builder-lite Wordpress<=1.3.6
Event History
Oct 26, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15919?
The severity of CVE-2017-15919 is classified as critical due to its potential for SQL injection and PHP object injection.
2
How do I fix CVE-2017-15919?
To fix CVE-2017-15919, update the Ultimate Form Builder Lite plugin to version 1.3.7 or later.
3
What is the impact of CVE-2017-15919?
The impact of CVE-2017-15919 includes unauthorized database access and possible remote code execution through object injection.
4
Which versions of Ultimate Form Builder Lite are affected by CVE-2017-15919?
All versions of Ultimate Form Builder Lite prior to 1.3.7 are affected by CVE-2017-15919.
5
Is CVE-2017-15919 a known vulnerability in WordPress plugins?
Yes, CVE-2017-15919 is a known vulnerability in the Ultimate Form Builder Lite plugin used in WordPress.