Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Missing Authorization

2024-04-11 00:00
Duc Manh

Strategic Overview

Status
Patched in 1.9.0
Affected Version<= 1.8.9
CVSS4.3Medium
CVECVE-2024-1416
View all Lead Form Builder & Contact Form vulnerabilities

Vulnerability Overview

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions.

Technical Analysis

REMEDIATION: Update to version 1.9.0, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C