PT-2023-32084 · WordPress · Funnelforms Free

Alex Thomas

+1

·

Published

2023-11-22

·

Updated

2025-05-12

·

CVE-2023-5386

CVSS v3.1
6.5
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Name of the Vulnerable Software and Affected Versions:

Funnelforms Free plugin for WordPress versions up to and including 3.4

Description:

The issue allows authenticated attackers with subscriber-level permissions and above to modify data without proper authorization. This is due to a missing capability check on the `fnsf delete posts` function, enabling them to delete arbitrary posts, including those of administrators and posts unrelated to the Funnelforms Free plugin.

Recommendations:

For versions up to and including 3.4, consider disabling the `fnsf delete posts` function until a patch is available to prevent unauthorized post deletion. Restrict access to the Funnelforms Free plugin's functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-5386

Affected Products

Funnelforms Free