Vulnerabilities > Accesspressthemes > Ultimate Form Builder Lite > 1.0.4

DATE CVE VULNERABILITY TITLE RISK
2017-10-26 CVE-2017-15919 SQL Injection vulnerability in Accesspressthemes Ultimate-Form-Builder-Lite
The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.
network
low complexity
accesspressthemes CWE-89
critical
9.8