Description
WordPress Plugin Contact Form for WordPress-Ultimate Form Builder Lite is prone to multiple vulnerabilities, including cross-site scripting and SQL injection vulnerabilities. Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, allowing the attacker to steal cookie-based authentication credentials, or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Contact Form for WordPress-Ultimate Form Builder Lite version 1.3.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.8 or latest
References
https://www.exploit-db.com/exploits/44884/
https://plugins.svn.wordpress.org/ultimate-form-builder-lite/trunk/readme.txt
Related Vulnerabilities
MySQL CVE-2015-4866 Vulnerability (CVE-2015-4866)
Oracle JRE CVE-2012-1682 Vulnerability (CVE-2012-1682)
MySQL CVE-2018-2665 Vulnerability (CVE-2018-2665)
WordPress Plugin StreamCast-Radio Player for WordPress Cross-Site Scripting (2.1)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (4.10.7)