Caldera Forms Pro < 1.8.2 - Missing Authorization

2019-03-13 00:00
Marc-Alexandre Montpas

Strategic Overview

Status
Patched in 1.7.7
Affected PluginCaldera Forms Pro
Affected Version1.7.6 – < 1.8.2 · 2 branches
CVSS9.8Critical
CVEN/A
View all Caldera Forms Pro vulnerabilities

Vulnerability Overview

The Caldera Forms Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the register_rest_route function in versions, up to and including, 1.7.6 in the 1.7.x branch, and 1.8.1 in the 1.8.x branch. This makes it possible for unauthenticated attackers to read arbitrary files, including wp-config.php.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 1.7.7, 1.8.2 --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C