First published: Mon Sep 19 2022(Updated: )
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Basix NEX-Forms – Ultimate Form Builder | <7.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-3142.
The severity of CVE-2022-3142 is high.
The affected software for CVE-2022-3142 is the NEX-Forms WordPress plugin before version 7.9.7.
CVE-2022-3142 allows SQL injections in the affected NEX-Forms WordPress plugin before version 7.9.7.
Yes, updating the NEX-Forms WordPress plugin to version 7.9.7 or higher fixes CVE-2022-3142.