Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j65x-2556-f67f

Опубликовано: 04 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.

EPSS

Процентиль: 13%
0.00224
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.8
nvd
около 2 месяцев назад

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.

EPSS

Процентиль: 13%
0.00224
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-89