Vulnerability Description
Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rayanehdownload | Rk-Responsive-Contact-Form | 1.0 |
Related Weaknesses (CWE)
References
- http://www.vapidlabs.com/advisory.php?v=198ExploitPatchThird Party Advisory
- https://wordpress.org/plugins/rk-responsive-contact-form/ProductThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8889Third Party Advisory
- http://www.vapidlabs.com/advisory.php?v=198ExploitPatchThird Party Advisory
- https://wordpress.org/plugins/rk-responsive-contact-form/ProductThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8889Third Party Advisory
FAQ
What is CVE-2017-1002027?
CVE-2017-1002027 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.p...
How severe is CVE-2017-1002027?
CVE-2017-1002027 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-1002027?
Check the references section above for vendor advisories and patch information. Affected products include: Rayanehdownload Rk-Responsive-Contact-Form.