Caldera Forms Pro < 1.8.2 - Missing Authorization
2019-03-13 00:00
Marc-Alexandre MontpasStrategic Overview
StatusPatched in 1.7.7
Affected PluginCaldera Forms Pro
Affected Version
1.7.6 – < 1.8.2 · 2 branchesCVSS9.8Critical
CVE
N/AVulnerability Overview
The Caldera Forms Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the register_rest_route function in versions, up to and including, 1.7.6 in the 1.7.x branch, and 1.8.1 in the 1.8.x branch. This makes it possible for unauthenticated attackers to read arbitrary files, including wp-config.php.
Technical Analysis
REMEDIATION: Update to one of the following versions, or a newer patched version: 1.7.7, 1.8.2 --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C