CyberRota Analysis
AI-GeneratedThe jet-form-builder-stripe-gateway plugin for WordPress prior to version 1.1.0 is vulnerable due to inadequate sanitization and escaping of payment tokens in SQL statements. This flaw allows unauthenticated users to execute SQL injection attacks, potentially leading to the extraction of sensitive data such as password hashes from the database. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data breaches.
Original NVD Description
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.