CVE-2017-18570: Cformsii Project Cformsii
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
Affected products
- Cformsii Project Cformsii: before 14.13 (fixed in 14.13)
Published 2019-08-22. Last modified 2026-06-17.