CRITICAL
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9
Published Jul 18, 2019
9.8
CRITICALCVSS 3.1
EPSS 2.58%
Description
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php
Affected products
No data.
- ≤ 1.4.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5029 Advisory
- https://fortiguard.com/zeroday/FG-VD-19-096 x_refsource_CONFIRMNot Applicable
- https://github.com/wpeverest/everest-forms/commit/755d095fe0d9a756a13800d1513cf98219e4a3f9 x_refsource_MISCPatch
- https://github.com/wpeverest/everest-forms/commit/755d095fe0d9a756a13800d1513cf98219e4a3f9#diff-bb2b21ef7774df8687ff02b0284505c6 x_refsource_MISCPatch
- https://wordpress.org/plugins/everest-forms/#developers x_refsource_MISCRelease Notes
- https://wpvulndb.com/vulnerabilities/9466 x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5029 | Advisory | |
| https://fortiguard.com/zeroday/FG-VD-19-096 | x_refsource_CONFIRMNot Applicable | |
| https://github.com/wpeverest/everest-forms/commit/755d095fe0d9a756a13800d1513cf98219e4a3f9 | x_refsource_MISCPatch | |
| https://github.com/wpeverest/everest-forms/commit/755d095fe0d9a756a13800d1513cf98219e4a3f9#diff-bb2b21ef7774df8687ff02b0284505c6 | x_refsource_MISCPatch | |
| https://wordpress.org/plugins/everest-forms/#developers | x_refsource_MISCRelease Notes | |
| https://wpvulndb.com/vulnerabilities/9466 | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 18, 2019
Updated Aug 4, 2024
Reserved Jul 12, 2019
Link CVE-2019-13575
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-5029 Assigner mitre
Published Jul 18, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-5029