Input validation vulnerability in WDContactFormBuilder 1.0.24

The Contact Form Builder plugin for WordPress is vulnerable to a type of attack called blind SQL Injection in version 1.0.24 and earlier. This type of attack can allow someone with access to the Admin area of the website to extract sensitive information from the database. This happens because the plugin does not properly escape user supplied data and insufficiently prepares the existing SQL query.

Detected in:

WDContactFormBuilder open vulnerable versions: >= * <= 1.0.24

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.