PT-2024-15505 · WordPress · Views For Wpforms
Francesco Carlucci
·
Published
2024-02-05
·
Updated
2024-02-09
·
CVE-2024-0370
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress versions up to, and including, 3.2.2
Description
The issue is related to a missing capability check on the
save view function, allowing authenticated attackers with subscriber access and above to modify the titles of arbitrary posts. This makes it possible for attackers to unauthorizedly modify data.Recommendations
For versions up to, and including, 3.2.2, consider disabling the
save view function until a patch is available to prevent unauthorized modification of data. Restrict access to modify post titles to minimize the risk of exploitation.Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Views For Wpforms