SQL Injection Vulnerability in Ultimate Form Builder Lite Plugin for WordPress
CVE-2017-15919
9.8CRITICAL
What is CVE-2017-15919?
The Ultimate Form Builder Lite plugin for WordPress before version 1.3.7 is susceptible to SQL Injection, which can lead to PHP Object Injection through the endpoint wp-admin/admin-ajax.php. This vulnerability can allow attackers to execute arbitrary SQL code on the database, potentially leading to unauthorized access and manipulation of data. Proper validation and sanitization of user input are critical to mitigate such risks.