S4E just found an informational finding from web sayfası erişilebilirlik kontrolü
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2024-30498

9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
crm perks formscrm_perks_forms
Updated Sep 18, 2026View on NVD →
S4E scanner

CRM Perks Forms <= 1.1.4 - SQL Injection

CRM Perks CRM Perks Forms (affected versions 1.1.4 and earlier) contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL commands, exploit requires user interaction. References: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/crm-perks-forms/crm-perks-forms-114-unauthenticated-sql-injection https://patchstack.com/database/wordpress/plugin/crm-perks-forms/vulnerability/wordpress-crm-perks-forms-plugin-1-1-4-unauthenticated-sql-injection-vulnerability https://nvd.nist.gov/vuln/detail/CVE-2024-30498 Remediation: Update to the latest version of CRM Perks Forms, version 1.1.5 or later.

Used 2.3k times · 2 assets checked · domain, subdomain, ipv4

CVE history: crm perks forms

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →