Input validation vulnerability in Contact Form by WD – responsive drag & drop contact form builder tool 1.7.31

The Contact Form Maker plugin for WordPress is vulnerable to a type of attack known as blind SQL injection in versions earlier than 1.7.31. This attack occurs because the plugin does not properly escape user supplied data or prepare existing SQL queries. Attackers with administrator-level privileges may be able to use this vulnerability to extract sensitive information from the website’s database.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.