PT-2024-16390 · WordPress · Wpforms

Asaf Mozes

·

Published

2024-11-13

·

Updated

2025-07-10

·

CVE-2024-10593

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress versions up to, and including, 1.9.1.6
Description The issue is related to Cross-Site Request Forgery due to missing or incorrect nonce validation on the process admin ui function. This allows unauthenticated attackers to delete WPForm logs via a forged request if they can trick a site administrator into performing an action such as clicking on a link.
Recommendations For versions up to, and including, 1.9.1.6, update to a version that includes the fix for the nonce validation issue in the process admin ui function. As a temporary workaround, consider restricting access to the process admin ui function to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-10593

Affected Products

Wpforms