High
CVSS 7.2
Overview
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape ...
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
This vulnerability is rated 🟠 HIGH.
Recommended actions: