Critical severity9.8NVD Advisory· Published Oct 26, 2017· Updated May 13, 2026
CVE-2017-15919
CVE-2017-15919
Description
The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.
Affected products
1- cpe:2.3:a:accesspressthemes:ultimate-form-builder-lite:*:*:*:*:*:wordpress:*:*Range: <=1.3.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/101604nvdThird Party AdvisoryVDB Entry
- wordpress.org/plugins/ultimate-form-builder-lite/nvdRelease NotesThird Party Advisory
- wpvulndb.com/vulnerabilities/8935nvdThird Party Advisory
- www.wordfence.com/blog/2017/10/zero-day-vulnerability-ultimate-form-builder-lite/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.