CVE-2019-9568: SQL Injection
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Forminator Contact Form Poll & Quiz Builder plugin?
The vulnerability ID for the Forminator Contact Form Poll & Quiz Builder plugin is CVE-2019-9568.
What is the severity of CVE-2019-9568?
The severity of CVE-2019-9568 is medium.
How does CVE-2019-9568 work?
CVE-2019-9568 is a SQL Injection vulnerability that can be exploited via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
What is the affected software for CVE-2019-9568?
The affected software for CVE-2019-9568 is the Forminator Contact Form, Poll & Quiz Builder plugin before version 1.6 for WordPress.
How can I fix CVE-2019-9568?
To fix CVE-2019-9568, update to version 1.6 or later of the Forminator Contact Form, Poll & Quiz Builder plugin.