PT-2024-16635 · WordPress · Pojo Forms
Arkadiusz Hydzik
·
Published
2024-12-06
·
Updated
2024-12-06
·
CVE-2024-10909
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Pojo Forms plugin for WordPress versions 1.4.7 and earlier
Description
The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via the
form preview shortcode AJAX action. This is due to the software allowing users to execute an action that does not properly validate a value before running do shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.Recommendations
For versions 1.4.7 and earlier, update to version 1.4.8 or later to partially fix the issue. As a temporary workaround, consider restricting access to the
form preview shortcode AJAX action to minimize the risk of exploitation. Additionally, restrict the execution of arbitrary shortcodes to prevent potential attacks.Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pojo Forms