PT-2024-39769 · WordPress · Forminator Forms

Vijaysimha

+1

·

Published

2024-10-30

·

Updated

2024-11-25

·

CVE-2024-9700

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress versions up to, and including, 1.36.0
Description The issue is related to Insecure Direct Object Reference, which allows unauthenticated attackers to modify other users' quiz submissions due to missing validation on the entry id user-controlled key. This is possible via the submit quizzes() function.
Recommendations For versions up to, and including, 1.36.0, update to a version that includes a fix for this issue. As a temporary workaround, consider disabling the submit quizzes() function until a patch is available. Restrict access to the entry id key to minimize the risk of exploitation.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-9700

Affected Products

Forminator Forms