CVE Database /
CVE-2014-9309
CVE
CVE-2014-9309 — Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2014-9309
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.0 |
— |
Unknown
|
< 2.0
|
2.0 |
0000-00-00 |
—
|
CVE-2014-9309
The Formidable Form Builder plugin for WordPress contains a blind SQL injection vulnerability in versions up to 1.07.11 affecting the 'orderby' parameter, which arises from improper escaping of user input and inadequately prepared SQL statements. Authenticated users with subscriber-level access or higher can exploit this flaw to inject additional SQL commands into existing queries, enabling them to retrieve sensitive data from the database.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings