WordPress Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration Plugin <= 1.75.0 is vulnerable to SQL Injection
CVE-2023-50853

7.6HIGH

Summary

An SQL Injection vulnerability has been identified in the Nasirahmed Advanced Form Integration plugin for WordPress, potentially allowing attackers to manipulate SQL queries to gain unauthorized access to sensitive data. This issue affects versions up to 1.75.0 and could be exploited by an attacker to execute arbitrary SQL commands, undermining the integrity and confidentiality of the database. It is crucial for users of the affected plugin to apply the necessary updates and follow security best practices to mitigate potential risks.

Affected Version(s)

Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.75.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Daffa (Patchstack Alliance)
.