First published: Mon Nov 28 2022(Updated: )
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibericode Html Forms Wordpress | <1.3.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3689 has a high severity rating due to the potential for SQL injection by high privilege users.
To fix CVE-2022-3689, update the HTML Forms WordPress plugin to version 1.3.25 or later.
CVE-2022-3689 affects users of the HTML Forms WordPress plugin versions prior to 1.3.25.
CVE-2022-3689 is classified as a SQL injection vulnerability.
No, CVE-2022-3689 can only be exploited by high privilege users.