Quasar form free – Contact Form Builder for WordPress [quasar-form] <= 6.1 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nucleus_genius Quasar form free – Contact Form Builder for WordPress allows SQL Injection.This issue affects Quasar form free – Contact Form Builder for WordPress: from n/a through 6.0.
- Affected:
- up to 6.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 3, 2023
CVE-2023-35910 on NVD →
Quasar form <= 6.1 - Authenticated (Subscriber+) SQL Injection via 'id'
high
The Quasar form plugin for WordPress is vulnerable to SQL Injection via the 'id' shortcode attribute in versions up to, and including, 6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with s...
- CVSS:
- 8.8
- Affected:
- up to 6.1
- Fix:
- No patched version reported
- Disclosed:
- Jul 24, 2023
CVE-2023-35910 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database