S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-3142 Scanner

CVE-2022-3142 scanner - SQL Injection vulnerability in NEX-Forms

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-3142
8.8
CVSS

The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
NEX-Forms – Ultimate Form Builder – Contact forms and much more
AFFECTED< 7.9.7SAFE ✓≥ 7.9.7
Updated Aug 22, 2026View on NVD →
Detail

NEX-Forms is a powerful and comprehensive form builder plugin for WordPress, designed to help users create and manage interactive forms for their websites easily. It is used by website owners, bloggers, and businesses to gather information from their visitors through customized forms, including contact forms, feedback surveys, and registration forms. This plugin provides a wide range of features such as drag-and-drop form building, responsive design, and advanced analytics, making it a popular choice for creating professional-looking forms without requiring coding skills.

The SQL Injection vulnerability in versions of NEX-Forms before 7.9.7 arises from the plugin's failure to adequately sanitize and escape user inputs before incorporating them into SQL queries. This security flaw allows attackers with access to the forms statistics chart, typically administrators or users with specific permissions set through plugin settings, to inject malicious SQL code. This could lead to unauthorized access to the website's database, data leakage, or manipulation.

Specifically, the vulnerability is located in the functionality that generates the forms statistics chart within the NEX-Forms dashboard. An attacker can exploit this by manipulating form IDs in requests to execute arbitrary SQL commands. The lack of proper input validation and parameterized queries allows the injection of SQL code, which can be executed by the database server, potentially compromising the integrity and confidentiality of the stored data.

Exploitation of this SQL Injection vulnerability could have severe consequences, including unauthorized access to sensitive data stored in the WordPress database, such as user information, passwords, and private form submissions. Attackers could also manipulate or delete data, leading to disruption of website operations and loss of trust among users. In extreme cases, it could facilitate further attacks on the website or its users.

S4E's advanced scanning technology enables you to identify and rectify vulnerabilities like SQL Injection in your WordPress plugins, ensuring your website remains secure against potential cyber-attacks. By becoming a member, you gain access to comprehensive vulnerability assessments, regular updates on new threats, and expert recommendations for maintaining a robust security posture. Protect your digital assets and build trust with your users by leveraging the proactive cyber threat management services offered by S4E.

 

References

Solution Advice
  1. Update the NEX-Forms plugin to version 7.9.7 or later immediately to patch the SQL Injection vulnerability.
  2. Ensure that all WordPress plugins and themes are regularly updated to their latest versions.
  3. Limit the access rights to sensitive plugin functionalities only to trusted administrators.
  4. Implement database access controls and use web application firewalls (WAFs) to detect and prevent SQL Injection attacks.
  5. Conduct regular security audits of your WordPress site to detect and fix vulnerabilities promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.