Caldera Forms – More Than Contact Forms < 1.4.0 - Sensitive Information Disclosure

2016-05-24 00:00
Panagiotis Vagenas

Strategic Overview

Status
Patched in 1.4.0
Affected Version< 1.4.0
CVSS6.5Medium
CVEN/A
View all Caldera Forms – More Than Contact Forms vulnerabilities

Vulnerability Overview

The Caldera Forms – More Than Contact Forms plugin for WordPress is vulnerable to Sensitive Information Disclosure due to missing capability checks on the browse_entries() function that makes it possible for low-level authenticated attackers to retrieve form entries in versions up to 1.4.0.

Technical Analysis

REMEDIATION: Update to version 1.4.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C