First published: Mon May 08 2023(Updated: )
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Basix NEX-Forms – Ultimate Form Builder | <8.4 | |
<8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2114 has a high severity level due to its potential for SQL injection attacks.
To fix CVE-2023-2114, update the NEX-Forms WordPress plugin to version 8.4 or later.
Exploiting CVE-2023-2114 can lead to unauthorized access to the database and manipulation of sensitive data.
CVE-2023-2114 affects all versions of NEX-Forms prior to version 8.4.
Yes, CVE-2023-2114 is classified as an SQL injection vulnerability due to improper input handling.