Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
ultimate-form-builder-lite vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id

WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the ufbl_get_entry_detail_action action to extract, modify, or escalate privileges within the WordPress database.

CWE-89May 23, 2026
CVSS7.1v4.0EPSS0.214%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX