PT-2025-17901 · WordPress · Ws Form Lite

Amin Beheshti

·

Published

2025-04-25

·

Updated

2025-04-25

·

CVE-2025-3912

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WS Form LITE – Drag & Drop Contact Form Builder for WordPress versions prior to 1.10.36
Description The issue allows unauthorized access to data due to a missing capability check on the get config function. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services.
Recommendations For WS Form LITE – Drag & Drop Contact Form Builder for WordPress versions prior to 1.10.36, update to version 1.10.36 or later to resolve the issue. As a temporary workaround, consider restricting access to the get config function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-3912

Affected Products

Ws Form Lite