PT-2024-16248 · WordPress · The Forminator Forms
Wesley
·
Published
2024-10-26
·
Updated
2024-10-28
·
CVE-2024-10402
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress versions up to, and including, 1.35.1
Description
The issue arises from a missing capability check on a function, allowing authenticated attackers with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms. This includes the ability to update the default registration role to Administrator on User Registration forms.
Recommendations
For versions up to, and including, 1.35.1, update to a version higher than 1.35.1 to resolve the issue.
As a temporary workaround, consider restricting access to the form editing functionality to prevent unauthorized modifications until a patch is available.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Forminator Forms