Form Manager <= 1.7.2 - Authenticated Remote Command Execution
highEval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote attackers to execute arbitrary code via unspecified vectors.
- CVSS:
- 8.8
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.3
- Disclosed:
- Jun 8, 2021