Everest Forms <= 1.4.9 - SQL Injection

Affects Plugin

References

CVE 2019-13575
URL https://fortiguard.com/zeroday/FG-VD-19-096
URL https://www.fortinet.com/blog/threat-research/wordpress-plugin-sql-injection-vulnerability.html
URL https://github.com/wpeverest/everest-forms/commit/755d095fe0d9a756a13800d1513cf98219e4a3f9#diff-bb2b21ef7774df8687ff02b0284505c6

Classification

Type SQLI
OWASP Top 10 A1: Injection
CWE CWE-89

Miscellaneous

Original Researcher Tin Duong
Submitter Ryan Dewhurst
Submitter Website https://wpscan.io
Submitter Twitter ethicalhack3r
Views 4750
Verified No
WPVDB ID 9466

Timeline

Publicly Published 2019-07-18 (5 months ago)
Added 2019-07-18 (5 months ago)
Last Updated 2019-11-28 (18 days ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin