CVE-2017-15919: Accesspressthemes Ultimate-Form-Builder-Lite

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.

Affected products

Published 2017-10-26. Last modified 2026-06-17.