CVE-2024-30242: high-severity vulnerability in IT Path Solutions Contact Form to Any API
WordPress Contact Form to Any API plugin <= 1.1.8 - Auth. SQL Injection vulnerability
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5epss 0.5%
exploitation probability
0.5%top 56% of all CVEs
observed exploitation
nono source reports it
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions Contact Form to Any API.This issue affects Contact Form to Any API: from n/a through 1.1.8.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Affected products
IT Path Solutions · Contact Form to Any APIRelated CVEs — IT Path Solutions Contact Form to Any API
In the same product, most dangerous first.