Security Advisory
CVE-2017-18570
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.