Vulnerabilities > Crmperks > Integration FOR Contact Form 7 AND Zoho CRM Bigin

DATE CVE VULNERABILITY TITLE RISK
2023-06-19 CVE-2023-2527 Cross-site Scripting vulnerability in Crmperks Integration for Contact Form 7 and Zoho Crm, Bigin 1.2.2
The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
network
low complexity
crmperks CWE-79
4.8
2023-05-26 CVE-2023-25976 Cross-Site Request Forgery (CSRF) vulnerability in Crmperks Integration for Contact Form 7 and Zoho Crm, Bigin
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions.
network
low complexity
crmperks CWE-352
8.8