Vulnerability Details CVE-2019-9568
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 69.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2019-9568
-
cpe:2.3:a:incsub:forminator:-
-
cpe:2.3:a:incsub:forminator:1.0
-
cpe:2.3:a:incsub:forminator:1.0.1
-
cpe:2.3:a:incsub:forminator:1.0.3
-
cpe:2.3:a:incsub:forminator:1.0.3.1
-
cpe:2.3:a:incsub:forminator:1.0.4
-
cpe:2.3:a:incsub:forminator:1.0.5
-
cpe:2.3:a:incsub:forminator:1.0.6
-
cpe:2.3:a:incsub:forminator:1.1.0
-
cpe:2.3:a:incsub:forminator:1.2.0
-
cpe:2.3:a:incsub:forminator:1.2.1
-
cpe:2.3:a:incsub:forminator:1.3.0
-
cpe:2.3:a:incsub:forminator:1.4.0
-
cpe:2.3:a:incsub:forminator:1.5.0
-
cpe:2.3:a:incsub:forminator:1.5.1
-
cpe:2.3:a:incsub:forminator:1.5.2
-
cpe:2.3:a:incsub:forminator:1.5.3
-
cpe:2.3:a:incsub:forminator:1.5.3.1
-
cpe:2.3:a:incsub:forminator:1.5.4