← back
CVE-2017-20244highCWE-89

Wow Forms WordPress Plugin 2.1 SQL Injection

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.8epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the 'send_mwp_form' action to extract sensitive database contents.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Wow-Company · Wow Forms
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.