Extension WordPress

Vulnérabilités Contact Form by WD – responsive drag & drop contact form builder tool

Cette page rassemble les failles publiées pour Contact Form by WD – responsive drag & drop contact form builder tool, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
0Critiques
3Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Contact Form by WD – responsive drag & drop contact form builder tool

4 fiches

CVE-2023-2655 Moyenne · 6,6
Contact Form by WD – responsive drag & drop contact form builder tool

Contact Form Maker <= 1.13.23 – Authenticated (Administrator+) SQL Injection

The Contact Form Maker plugin for WordPress is vulnerable to blind SQL Injection in versions before 1.13.23 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

*-1.13.23

Correctif

Non indiqué

Publication

15/06/2023

CVE-2019-11591 Élevée · 8,8
Contact Form by WD – responsive drag & drop contact form builder tool

Contact Form by WD <= 1.13.4 – Cross-Site Request Forgery

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value,…

Versions affectées

[*, 1.13.5)

Correctif

1.13.5

Publication

05/04/2019

Vulnérabilité Élevée · 7,2
Contact Form by WD – responsive drag & drop contact form builder tool

Contact Form Maker <= 1.7.30 – Authenticated (Admin+) SQL Injection

The Contact Form Maker plugin for WordPress is vulnerable to blind SQL Injection via the ‘form_id’ parameter in versions before 1.7.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

[*, 1.7.31)

Correctif

1.7.31

Publication

24/11/2015

Vulnérabilité Élevée · 8,1
Contact Form by WD – responsive drag & drop contact form builder tool

Contact Form by WD – responsive drag & drop contact form builder tool <= 1.7.18 – Authorization Bypass

The Contact Form by WD – responsive drag & drop contact form builder tool plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the form_maker_cfm function in versions up to, and including,…

Versions affectées

*-1.7.18

Correctif

1.7.19

Publication

09/11/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités