PT-2024-38357 · WordPress · Funnelforms Free

Lucio Sá

·

Published

2024-08-28

·

Updated

2024-09-13

·

CVE-2024-7447

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Funnelforms Free plugin for WordPress versions up to, and including, 3.7.3.2
Description The issue is related to unauthorized modification of data due to a missing capability check on the fnsf af2 handel file upload function. This allows unauthenticated attackers to upload arbitrary media to the site, even if no forms exist.
Recommendations For versions up to, and including, 3.7.3.2, consider disabling the fnsf af2 handel file upload function until a patch is available to prevent unauthorized media uploads. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7447

Affected Products

Funnelforms Free