CRM Perks Forms <= 1.1.4 - SQL Injection
CVE-2024-30498
Verified
Description
CRM Perks CRM Perks Forms (affected versions 1.1.4 and earlier) contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL commands, exploit requires user interaction.
Severity
Critical
CVSS Score
9.3
Exploit Probability
2%
Published Date
March 8, 2026
Template Author
shivam kamboj
CVE-2024-30498.yaml
9.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
CVE ID:
cve-2024-30498
CWE ID:
cwe-89
References
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/crm-perks-forms/crm-perks-forms-114-unauthenticated-sql-injectionhttps://patchstack.com/database/wordpress/plugin/crm-perks-forms/vulnerability/wordpress-crm-perks-forms-plugin-1-1-4-unauthenticated-sql-injection-vulnerabilityhttps://nvd.nist.gov/vuln/detail/CVE-2024-30498
Remediation Steps
Update to the latest version of CRM Perks Forms, version 1.1.5 or later.