WordPress Ultimate Addons for Contact Form 7 Plugin <= 3.1.23 is vulnerable to SQL Injection
CVE-2023-30495
8.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 December 2023
What is CVE-2023-30495?
An SQL Injection vulnerability exists in the Themefic Ultimate Addons for Contact Form 7, allowing attackers to manipulate SQL queries. This flaw affects the plugin versions from n/a up to 3.1.23, compromising the security of applications that utilize it. Proper validation and sanitization of inputs are critical to prevent unauthorized access to the database and protect sensitive data.
Affected Version(s)
Ultimate Addons for Contact Form 7 <= 3.1.23