CVE-2018-21003: SQL Injection
Published Aug 27, 2019
·Updated
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
Affected Software
1 affected component
ThemeKraft Buddyforms Wordpress<2.2.8
Event History
Aug 27, 2019
CVE Published
via MITRE·11:26 AM
Data Sourced
via MITRE·11:26 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-21003.
2
What is the title of the vulnerability?
The title of the vulnerability is 'The buddyforms plugin before 2.2.8 for WordPress has SQL injection.'
3
What is the severity of the vulnerability?
The severity of the vulnerability is critical.
4
What software is affected by the vulnerability?
The affected software is Themekraft Buddyforms version up to 2.2.8 for WordPress.
5
How can I fix the vulnerability?
To fix the vulnerability, update the buddyforms plugin to version 2.2.8 or higher.