ultimate-form-builder-lite Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with ultimate-form-builder-lite products.
Products
- Ultimate Form Builder Lite1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-25352HIGH | WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_idWordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the ufbl_get_entry_detail_action action to extract, modify, or escalate privileges within the WordPress database. CWE-89May 23, 2026 | CVSS7.1v4.0 | EPSS0.214% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |