First published: Mon Mar 04 2019(Updated: )
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Forminator | <1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Forminator Contact Form Poll & Quiz Builder plugin is CVE-2019-9568.
The severity of CVE-2019-9568 is medium.
CVE-2019-9568 is a SQL Injection vulnerability that can be exploited via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
The affected software for CVE-2019-9568 is the Forminator Contact Form, Poll & Quiz Builder plugin before version 1.6 for WordPress.
To fix CVE-2019-9568, update to version 1.6 or later of the Forminator Contact Form, Poll & Quiz Builder plugin.