WordPress Ultimate Addons for Contact Form 7 Plugin <= 3.1.23 is vulnerable to SQL Injection
CVE-2023-30495
8.5HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 20 December 2023
Summary
An SQL Injection vulnerability exists in the Themefic Ultimate Addons for Contact Form 7, allowing attackers to manipulate SQL queries. This flaw affects the plugin versions from n/a up to 3.1.23, compromising the security of applications that utilize it. Proper validation and sanitization of inputs are critical to prevent unauthorized access to the database and protect sensitive data.
Affected Version(s)
Ultimate Addons for Contact Form 7 <= 3.1.23
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ivy - TOOR, LISA (Patchstack Alliance)