CVE-2023-29096: WordPress Contact Form to DB by BestWebSoft Plugin <= 1.7.0 is vulnerable to SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29096?
CVE-2023-29096 has a high severity due to its potential to allow SQL injection attacks.
How do I fix CVE-2023-29096?
To fix CVE-2023-29096, update the BestWebSoft Contact Form to DB plugin to version 1.8.0 or later.
Which versions are affected by CVE-2023-29096?
CVE-2023-29096 affects versions of the BestWebSoft Contact Form to DB plugin up to and including 1.7.0.
What type of vulnerability is CVE-2023-29096?
CVE-2023-29096 is an SQL injection vulnerability, which can be exploited to manipulate database queries.
Is there a recommended mitigation for CVE-2023-29096?
The recommended mitigation for CVE-2023-29096 is to immediately update to a patched version of the plugin.