PT-2026-33019 · Forfront · E-Shot
Phong Nguyen
·
Published
2026-04-15
·
Updated
2026-04-15
·
CVE-2026-3642
CVSS v3.1
5.3
Medium
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot form builder update field data() AJAX handler lacks any capability checks (current user can()) or nonce verification (check ajax referer()/wp verify nonce()). The function is registered via the wp ajax hook, making it accessible to any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify form field configurations including mandatory status, field visibility, and form display preferences via the eshot form builder update field data AJAX action.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E-Shot