Input validation vulnerability in FormCraft – Contact Form Builder for WordPress 3.9.5

The FormCraft Premium plugin for WordPress is vulnerable to a type of attack called SQL Injection. This attack can be used to access sensitive information from the website’s database, such as passwords and user information. This attack is possible on versions up to, and including, 3.9.6 of FormCraft Premium because the software does not properly secure the user supplied parameter and does not adequately prepare existing SQL queries to protect against the attack. Note that this vulnerability applies to the Premium version of FormCraft, even though it shares the same plugin slug as the free version.

Detected in:

FormCraft fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.