WordPress Plugin Vulnerabilities
Contact Form Submissions < 1.7.1 - Authenticated Double Query SQL injection
Description
The plugin is affected by a double query SQL injection, which could allow high privileged users to access data from the DBMS.
Edit (WPScanTeam)
October 26th, 2020 - Confirmed & Escalated to WP
October 27th, 2020 - WP Investigating
January 3rd, 2021 - No updates, disclosing
March 29th, 2021 - v1.7 released to attempt to remediate the issue using sanitize_text_field(), which does not fix the SQL injection
April 7th, 2021 - v1.7.1 released, fixing the issue
Proof of Concept
Affects Plugins
Classification
Type
SQLI
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Lenon Leite
Submitter
Lenon Leite
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-01-03 (about 4 years ago)
Added
2021-01-03 (about 4 years ago)
Last Updated
2021-04-08 (about 4 years ago)