Critical severity9.8NVD Advisory· Published Oct 17, 2017· Updated May 13, 2026
CVE-2015-7806
CVE-2015-7806
Description
Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote attackers to execute arbitrary code via unspecified vectors.
Affected products
3<1.7.3+ 1 more
- (no CPE)range: <1.7.3
- (no CPE)range: <1.7.3
- cpe:2.3:a:form_manager_project:form_manager:1.7.2:*:*:*:*:wordpress:*:*
Patches
1r1264145https://plugins.svn.wordpress.orgvia nvd-ref
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- appcheck-ng.com/remote-command-execution-in-wordpress-form-manager-plugin-cve-2015-7806/nvdExploitThird Party Advisory
- plugins.trac.wordpress.org/changeset/1264145nvdThird Party Advisory
- wpvulndb.com/vulnerabilities/8220nvdThird Party Advisory
News mentions
0No linked articles in our index yet.