CVE Published: 31/10/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: Patchstack |
Vendor: Contact Form - WPManageNinja LLC |
Product: Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms Status : PUBLISHED
CVE-2023-24410 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms: from n/a through 4.3.25.
CWE-ID: CWE-89 CWE Name: CWE-89 Improper Neutralization of Special Elements used in an SQL Command (
SQL Injection
) Source: Contact Form - WPManageNinja LLC
Common Attack Pattern Enumeration and Classification (CAPEC)