CVE-2023-31212: WordPress Contact Form Entries plugin <= 1.3.0 - Auth. SQL Injection (SQLi) vulnerability
Published Oct 31, 2023
·Updated
A vulnerability in CRM Perks Contact Form Entries contact-form-entries.This issue affects Contact Form Entries: from n/a through <= 1.3.0.
Affected Software
1 affected component
crmperks Database For Contact Form 7\, Wpforms\, Elementor Forms<=1.3.0
Remediation
Information
Update to 1.3.1 or a higher version.
Event History
Oct 31, 2023
CVE Published
via MITRE·02:04 PM
Data Sourced
via MITRE·02:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-31212?
CVE-2023-31212 is a vulnerability in the WordPress Contact Form Entries Plugin version 1.3.0 and below that allows for SQL Injection.
2
How severe is CVE-2023-31212?
CVE-2023-31212 has a severity rating of 9.8, which is considered critical.
3
Which software is affected by CVE-2023-31212?
The CRM Perks Database for Contact Form 7, WPforms, Elementor forms version up to and including 1.3.0 are affected by CVE-2023-31212.
4
How can I fix CVE-2023-31212?
To fix CVE-2023-31212, you should update the WordPress Contact Form Entries Plugin to a version above 1.3.0.
5
What is the CWE-ID of CVE-2023-31212?
The CWE-ID of CVE-2023-31212 is 89, which stands for Improper Neutralization of Special Elements in an SQL Command (SQL Injection).