CVE-2023-24410: WordPress FluentForm Plugin <= 4.3.25 is vulnerable to SQL Injection
Published Oct 31, 2023
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms: from n/a through 4.3.25.
Affected Software
1 affected component
FluentForms Contact Form Wordpress<=4.3.25
Remediation
Information
Update to 5.0.0 or a higher version.
Event History
Oct 31, 2023
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-24410.
2
What is the severity of CVE-2023-24410?
CVE-2023-24410 has a severity level of critical.
3
Which version of WordPress FluentForm Plugin is affected?
The vulnerability affects WordPress FluentForm Plugin versions up to and including 4.3.25.
4
What is the CWE ID associated with this vulnerability?
The CWE ID associated with CVE-2023-24410 is CWE-89.
5
Is there a patch available for this vulnerability?
Yes, a patch is available for this vulnerability. Please refer to the reference link for more information.