CVE-2017-18570: Cformsii Project Cformsii

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

Affected products

Published 2019-08-22. Last modified 2026-06-17.