First published: Thu May 23 2019(Updated: )
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
10web Form Maker | <1.13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Form Maker plugin vulnerability is CVE-2019-10866.
The severity level of CVE-2019-10866 is critical with a severity value of 9.8.
The SQL injection vulnerability in the Form Maker plugin occurs in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
The version affected by CVE-2019-10866 is up to exclusive version 1.13.3 of the Form Maker plugin for WordPress.
You can find more information about CVE-2019-10866 at the following references: [Link 1](http://seclists.org/fulldisclosure/2019/May/8), [Link 2](https://wordpress.org/plugins/form-maker/#developers), [Link 3](https://wpvulndb.com/vulnerabilities/9286)