SQL Injection Vulnerability in Nex-Forms Express WP Form Builder by WordPress
CVE-2015-9452
9.8CRITICAL
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 7 October 2019
Summary
A vulnerability exists in the Nex-Forms Express WP Form Builder plugin prior to version 4.6.1, allowing attackers to perform SQL injection attacks via the nex_forms_Id
parameter in the wp-admin/admin.php?page=nex-forms-main
endpoint. This flaw can potentially enable unauthorized access to sensitive information or facilitate further exploitation of the affected system. Website owners using this plugin are advised to update to the latest version to mitigate these risks.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved