CVE-2017-15919
26.10.2017, 18:29
The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.
Vendor | Product | Version |
---|---|---|
accesspressthemes | ultimate-form-builder-lite | 𝑥 ≤ 1.3.6 |
𝑥
= Vulnerable software versions
References