Description
WordPress Plugin Form Store to DB [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Form Store to DB version 1.0.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.0 or latest
References
Related Vulnerabilities
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-9127)
WordPress Plugin A.M.Y. Cross-Site Scripting (1.3.3)
Python Out-of-bounds Write Vulnerability (CVE-2018-25032)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Request Forgery (2.25.2)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-5498)