CVE-2017-15919
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 2.5%
from disclosure to weapon
Published on NVDOct 26
VulnCheckOct 23
exploitation probability
2.5%top 16% of all CVEs
observed exploitation
yesVulnCheck
The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.
Affected products
n/a · n/a