WordPress Plugin Vulnerabilities

Contact Form Submissions < 1.7.1 - Authenticated Double Query SQL injection

Description

The plugin is affected by a double query SQL injection, which could allow high privileged users to access data from the DBMS.

Edit (WPScanTeam)
October 26th, 2020 - Confirmed & Escalated to WP
October 27th, 2020 - WP Investigating
January 3rd, 2021 - No updates, disclosing
March 29th, 2021 - v1.7 released to attempt to remediate the issue using sanitize_text_field(), which does not fix the SQL injection
April 7th, 2021 - v1.7.1 released, fixing the issue

Proof of Concept

Affects Plugins

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Lenon Leite
Submitter
Lenon Leite
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-01-03 (about 4 years ago)
Added
2021-01-03 (about 4 years ago)
Last Updated
2021-04-08 (about 4 years ago)

Other