CVE-2013-7187 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 4.8% (pctl 92)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 4.79% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-12-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ncrafts | formcraft |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin Formcraft - SQL Injection | 2013-12-02 |
References
- http://packetstormsecurity.com/files/124343/wpformcraft-sql.txt
- http://secunia.com/advisories/56044
- http://www.exploit-db.com/exploits/30002
- http://www.securityfocus.com/bid/64183
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89581
- http://packetstormsecurity.com/files/124343/wpformcraft-sql.txt
- http://secunia.com/advisories/56044
- http://www.exploit-db.com/exploits/30002
- http://www.securityfocus.com/bid/64183
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89581
→ the Explorer · watch your stack · NVD