CVE-2023-2592


FormCraft Premium < 3.9.7 - Admin+ SQLi

The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.



We have discovered 7,675 live websites that are affected by CVE-2023-2592.

Contact us to get more info




Affected Software

Product  FormCraft
Category Wordpress Plugins
Vulnerable Versions
  • from 3.8.2 before 3.9.7
Total Vulnerable Versions83
Vulnerable Domains7,675 live websites (43.82% of FormCraft install base)


Common Weakness Enumeration


CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-2592 and the relative popularity of websites


Details

  • Published - Jun 27, 2023
  • Updated - Jun 27, 2023

Credits

  • Chien Vuong (finder)
  • WPScan (coordinator)





Countries

United States1,708 websites



Germany682 websites
Brazil496 websites
GB434 websites
Italy408 websites
Canada298 websites
France273 websites
Spain206 websites
South Africa197 websites
Russia194 websites

TLDs

.com2,963 websites
.de490 websites
.com.br436 websites
.it267 websites
.co.uk252 websites
.org252 websites
.ca145 websites
.ru142 websites
.com.au138 websites
.nl136 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-2592 through included software libraries and plugins.



References


Websites affected by CVE-2023-2592

Top websites that are affected by CVE-2023-2592. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
************.com United States*,***
***.************.com Bulgaria**,***
********.com United States**,***
***.*****.gov United States**,***
***.*****.edu United States**,***
*******.org United States***,***
***********.com Portugal***,***
***.****.de Germany***,***
******.com United States***,***
**********.at Austria***,***
See full domain list