First published: Tue Apr 23 2024(Updated: )
Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Forminator | <1.29.3 | |
WPForms Forminator | <1.29.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31077 has a high severity rating due to its potential for SQL injection and the ability for authenticated attackers to manipulate database information.
To fix CVE-2024-31077, upgrade to Forminator version 1.29.3 or higher as this version contains the necessary security patches.
CVE-2024-31077 affects all versions of Forminator prior to 1.29.3 installed on WordPress sites.
If CVE-2024-31077 is exploited, an attacker can alter database information and potentially achieve a denial-of-service condition.
Yes, CVE-2024-31077 requires the attacker to have remote authenticated access with administrative privileges to exploit the vulnerability.