SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ncrafts | formcraft | 1.3 |
| ncrafts | formcraft | 1.3.1 |
| ncrafts | formcraft | 1.3.3 |
| ncrafts | formcraft | 1.1 |
| ncrafts | formcraft | 1.2.1 |
| ncrafts | formcraft | 1.2 |
| ncrafts | formcraft | 1.3.2 |
| ncrafts | formcraft | 1.3.6 |
| ncrafts | formcraft | 1.3.5 |
| ncrafts | formcraft | * |
| ncrafts | formcraft | 1.3.4 |
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ncrafts | formcraft | * |
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ncrafts | formcraft | * |
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ncrafts | formcraft | * |