Calculated Fields Form <= 5.2.63 - Denial of Service
2024-12-16 00:00
Max Boll (_b0lli)Strategic Overview
StatusPatched in 5.2.64
Affected PluginCalculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
Affected Version
<= 5.2.63CVSS5.3Medium
CVE
CVE-2024-12601Vulnerability Overview
The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in slowing server resources if the server does not mitigate Denial of Service attacks.
Technical Analysis
REMEDIATION: Update to version 5.2.64, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C