Описание
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php.
Ссылки
- Mailing ListThird Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Release NotesThird Party Advisory
- Mailing ListThird Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.5 (включая)
cpe:2.3:a:cfpaypal:cp_contact_form_with_paypal:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 78%
0.01159
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 7.2
github
больше 3 лет назад
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php.
EPSS
Процентиль: 78%
0.01159
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89