CVE-2023-36508: WordPress Contact Form to DB by BestWebSoft plugin <= 1.7.1 - SQL Injection vulnerability
Published Oct 31, 2023
·Updated
A vulnerability in bestweblayout Contact Form to DB by BestWebSoft contact-form-to-db.This issue affects Contact Form to DB by BestWebSoft: from n/a through <= 1.7.1.
Affected Software
1 affected component
BestWebSoft Contact Form to DB<=1.7.1
Remediation
Information
Update to 1.7.2 or a higher version.
Event History
Oct 31, 2023
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-36508.
2
What is the title of the vulnerability?
The title of the vulnerability is WordPress Contact Form to DB by BestWebSoft Plugin <= 1.7.1 is vulnerable to SQL Injection.
3
What is the severity level of CVE-2023-36508?
The severity level of CVE-2023-36508 is critical (9.8).
4
What is the affected software?
The affected software is BestWebSoft Contact Form to DB by BestWebSoft Plugin version 1.7.1 and below.
5
How does the vulnerability affect the software?
The vulnerability allows SQL injection in the BestWebSoft Contact Form to DB by BestWebSoft Plugin.