First published: Mon Jun 19 2023(Updated: )
The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Crmperks Integration For Contact Form 7 And Zoho Crm, Bigin | <1.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Contact Form 7 and Zoho CRM plugin is CVE-2023-2527.
The severity of CVE-2023-2527 is medium with a severity value of 4.8.
The affected software for CVE-2023-2527 is the Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before version 1.2.4.
The risk of CVE-2023-2527 is a SQL injection vulnerability that can be exploited by high privilege users such as admin.
To fix CVE-2023-2527, update the Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin to version 1.2.4 or higher.