plugin

Quasar Form Vulnerabilities

2 known security issues reported for the Quasar Form WordPress plugin. Most recent disclosed Nov 3, 2023.

1 high

Running Quasar Form on your site? Check whether your installed version is affected.

Scan your site free

Quasar form free &#8211; Contact Form Builder for WordPress [quasar-form] <= 6.1 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nucleus_genius Quasar form free – Contact Form Builder for WordPress allows SQL Injection.This issue affects Quasar form free – Contact Form Builder for WordPress: from n/a through 6.0.

Affected:
up to 6.1
Fix:
No patched version reported
Disclosed:
Nov 3, 2023

CVE-2023-35910 on NVD →

Quasar form <= 6.1 - Authenticated (Subscriber+) SQL Injection via 'id'

high

The Quasar form plugin for WordPress is vulnerable to SQL Injection via the 'id' shortcode attribute in versions up to, and including, 6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with s...

CVSS:
8.8
Affected:
up to 6.1
Fix:
No patched version reported
Disclosed:
Jul 24, 2023

CVE-2023-35910 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database