Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the 'send_mwp_form' action to extract sensitive database contents.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the 'send_mwp_form' action to extract sensitive database contents. | |
| Title | Wow Forms WordPress Plugin 2.1 SQL Injection | |
| First Time appeared |
Wow-company
Wow-company wow Forms |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:wow-company:wow_forms:-:*:*:*:*:wordpress:*:* cpe:2.3:a:wow-company:wow_forms:2.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wow-company
Wow-company wow Forms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-09T13:09:54.048Z
Reserved: 2026-06-08T11:44:30.995Z
Link: CVE-2017-20244
Updated: 2026-06-09T13:09:50.803Z
Status : Received
Published: 2026-06-09T13:16:34.123
Modified: 2026-06-09T13:16:34.123
Link: CVE-2017-20244
No data.
OpenCVE Enrichment
No data.