First published: Mon Nov 06 2023(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rocklobster Contact Form 7 | =1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40609 is a SQL Injection vulnerability found in the WordPress Contact form 7 Custom validation Plugin version 1.1.3 and earlier.
CVE-2023-40609 is considered a critical vulnerability with a severity score of 9.8.
Contact form 7 Custom validation versions from n/a through 1.1.3 are affected.
To fix CVE-2023-40609, update the Contact form 7 Custom validation Plugin to a version newer than 1.1.3.
You can find more information about CVE-2023-40609 at the following link: [https://patchstack.com/database/vulnerability/cf7-field-validation/wordpress-contact-form-7-custom-validation-plugin-1-1-3-unauth-sql-injection-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/cf7-field-validation/wordpress-contact-form-7-custom-validation-plugin-1-1-3-unauth-sql-injection-vulnerability?_s_id=cve)