CVE-2017-1002027
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: larry0@me.com — http://www.vapidlabs.com/advisory.php?v=198
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| rayanehdownload | rk-responsive-contact-form | 1.0 | |
References
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.