CVE-2023-35911: WordPress Contact Form Generator Plugin <= 2.6.0 is vulnerable to SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-35911?
CVE-2023-35911 is a vulnerability in the WordPress Contact Form Generator Plugin <= 2.6.0 that allows for SQL Injection.
How does the SQL Injection vulnerability in WordPress Contact Form Generator Plugin work?
The SQL Injection vulnerability in WordPress Contact Form Generator Plugin allows an attacker to manipulate the SQL queries used by the plugin to execute arbitrary SQL commands.
What is the severity of CVE-2023-35911?
CVE-2023-35911 has a severity rating of critical with a CVSS score of 9.8.
How can I fix the SQL Injection vulnerability in WordPress Contact Form Generator Plugin?
To fix the SQL Injection vulnerability, you should update the WordPress Contact Form Generator Plugin to version 2.6.1 or later, which contains a patch for this vulnerability.
Where can I find more information about CVE-2023-35911?
You can find more information about CVE-2023-35911 at the following link: [CVE-2023-35911](https://patchstack.com/database/vulnerability/contact-form-generator/wordpress-contact-form-generator-plugin-2-6-0-sql-injection-vulnerability?_s_id=cve)