CVE-2022-47586: WordPress Ultimate Addons for Contact Form 7 Plugin <= 3.1.23 is vulnerable to SQL Injection
Published Jun 19, 2023
·Updated
Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.
Affected Software
1 affected component
Themefic Ultimate Addons For Contact Form 7 Wordpress<3.1.24
Remediation
Information
Update to 3.1.24 or a higher version.
Event History
Jun 19, 2023
CVE Published
via MITRE·11:58 AM
Data Sourced
via MITRE·11:58 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-47586?
CVE-2022-47586 is an unauthenticated SQL Injection (SQLi) vulnerability in the Themefic Ultimate Addons for Contact Form 7 plugin.
2
What versions of the Themefic Ultimate Addons for Contact Form 7 plugin are affected by CVE-2022-47586?
CVE-2022-47586 affects version 3.1.23 and all previous versions of the Themefic Ultimate Addons for Contact Form 7 plugin.
3
How severe is CVE-2022-47586?
CVE-2022-47586 has a severity rating of 9.8 (critical).
4
How can I fix CVE-2022-47586?
To fix CVE-2022-47586, update your Themefic Ultimate Addons for Contact Form 7 plugin to version 3.1.24 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-47586?
The CWE ID for CVE-2022-47586 is CWE-89 (SQL Injection).