CVE-2017-15919: Accesspressthemes Ultimate-Form-Builder-Lite
Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.
The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.
Affected products
- Accesspressthemes Ultimate-Form-Builder-Lite: up to and including 1.3.6
Published 2017-10-26. Last modified 2026-06-17.