Description
A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection. The attack may be initiated remotely. The patch is named 41230a81db0f671c570c2644bc2f80565ca83c5a. It is recommended to apply a patch to fix this issue.
References (3)
Core 3
Core References
Patch patch
https://github.com/webuidesigning/NebulaX/commit/41230a81db0f671c570c2644bc2f80565ca83c5a
Permissions Required, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.289163
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.289163
Scores
CVSS v3
6.3
EPSS
0.0034
EPSS Percentile
25.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
webuidesigning/NebulaX Theme
5.0
Published
Dec 23, 2024
Tracked Since
Feb 18, 2026