PT-2024-18299 · WordPress · Contact Form 7

Zulu Capwn

·

Published

2024-02-23

·

Updated

2025-01-16

·

CVE-2024-1778

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contact Form 7 plugin for WordPress versions up to, and including, 1.1.1
Description The Admin side data storage is vulnerable to unauthorized modification of data due to a missing capability check on the zt dcfcf change bookmark() function. This makes it possible for unauthenticated attackers to alter bookmark statuses.
Recommendations For versions up to, and including, 1.1.1, consider disabling the zt dcfcf change bookmark() function until a patch is available to prevent unauthorized modification of data.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1778

Affected Products

Contact Form 7