cleantalk
Vulnerabilities and Security Researches

Forminator – Contact Form, Payment Form & Custom Form Builder, CVE-2019-9568

CVE, Research URL

CVE-2019-9568

Published on
Mar 04, 2019
Research Description
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
Affected versions
Min -, max 1.6.
Status
vulnerable