First published: Sun Mar 31 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a through 3.7.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Form Builder | >=n/a<=3.7.4 | |
WPForms Easy Form Builder for WordPress | <=3.7.4 |
Update to 3.7.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30535 is classified as a critical SQL Injection vulnerability.
To fix CVE-2024-30535, upgrade the WhiteStudio Easy Form Builder to version 3.7.5 or later.
CVE-2024-30535 affects WhiteStudio Easy Form Builder versions from n/a up to 3.7.4.
Yes, CVE-2024-30535 can be exploited remotely by an attacker with knowledge of SQL injection techniques.
The potential impacts of CVE-2024-30535 include unauthorized access to the database and data manipulation.