Everest Forms <= 1.4.9 - SQL Injection

Affects Plugin

fixed in version 1.5.0

References

CVE 2019-13575
URL https://fortiguard.com/zeroday/FG-VD-19-096
URL https://github.com/wpeverest/everest-forms/commit/755d095fe0d9a756a13800d1513cf98219e4a3f9#diff-bb2b21ef7774df8687ff02b0284505c6

Classification

Type SQLI
OWASP Top 10 A1: Injection
CWE CWE-89

Miscellaneous

Original Researcher Tin Duong
Submitter Ryan Dewhurst
Submitter Website https://wpscan.io
Submitter Twitter ethicalhack3r
Views 3147
Verified No
WPVDB ID 9466

Timeline

Publicly Published 2019-07-18 (about 1 month ago)
Added 2019-07-18 (about 1 month ago)
Last Updated 2019-07-25 (about 1 month ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin