๐Ÿ” CVE Alert

CVE-2023-35911

CRITICAL 9.8

WordPress Contact Form Generator Plugin <= 2.6.0 is vulnerable to SQL Injection

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.

CWE CWE-89
Vendor creative solutions
Product contact form generator : creative form builder for wordpress
Published Nov 6, 2023
Last Updated Apr 28, 2026
Stay Ahead of the Next One

Get instant alerts for creative solutions contact form generator : creative form builder for wordpress

Be the first to know when new critical vulnerabilities affecting creative solutions contact form generator : creative form builder for wordpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Creative Solutions / Contact Form Generator : Creative form builder for WordPress
n/a โ‰ค 2.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/vulnerability/contact-form-generator/wordpress-contact-form-generator-plugin-2-6-0-sql-injection-vulnerability?_s_id=cve

Credits

Emili Castells (Patchstack Alliance)