CVE-2024-30242
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
28/03/2024
Last modified:
28/04/2026
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions Contact Form to Any API.This issue affects Contact Form to Any API: from n/a through 1.1.8.
Impact
Base Score 3.x
8.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://patchstack.com/database/vulnerability/contact-form-to-any-api/wordpress-contact-form-to-any-api-plugin-1-1-8-subscriber-sql-injection-vulnerability?_s_id=cve
- https://patchstack.com/database/vulnerability/contact-form-to-any-api/wordpress-contact-form-to-any-api-plugin-1-1-8-subscriber-sql-injection-vulnerability?_s_id=cve



