QID 150589
Date Published: 2022-11-03
QID 150589: WordPress Form Maker Plugin: Authenticated SQL Injection Vulnerability (CVE-2022-3300)
Form Maker by 10Web is the drag and drop plugin for building forms of any complexity in just a few clicks.
The plugin does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
Affected Versions:
WordPress Form Maker Plugin before 1.15.6.
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary SQL queries on the target system.
Solution
Customers are advised to upgrade to Form Maker 1.15.6 or later version to remediate this vulnerability. For more information regarding this vulnerability please refer WPScan Security Advisory
Vendor References
CVEs related to QID 150589
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WPScan |
|