WordPress Contact Form Maker Plugin 1.12.20 SQL Injection
Vulnerability Description
WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'name' and 'search_labels' parameters to extract sensitive database information or escalate privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25347
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Neven Biruski
References
More from web-dorado
View All →Affected Vendor
web-dorado
View all reports →