← volver
CVE-2023-32741

WordPress Contact Form to Any API Plugin <= 1.1.2 is vulnerable to SQL Injection

CVSS 7.6 HIGHEPSS 0.6%CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →