Showing 1 vulnerability on this page for ultimate-form-builder-lite

Signals CISA KEV Ransomware Nuclei
accesspressthemes vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

accesspressthemes ultimate-form-builder-lite Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.

CWE-89Oct 26, 2017
CVSS9.8v3.0EPSS2.48%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX