← back
CVE-2023-32741

WordPress Contact Form to Any API Plugin <= 1.1.2 is vulnerable to SQL Injection

CVSS 7.6 HIGHEPSS 0.6%CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →