Material Design for Contact Form 7 <= 2.6.4 - Missing Authorization to Arbitrary Settings Update

2022-03-11 00:00
Krzysztof Zając

Strategic Overview

Status
Unpatched
Affected Version<= 2.6.4
CVSS6.5Medium
CVECVE-2022-0404
View all Material Design for Contact Form 7 vulnerabilities

Vulnerability Overview

The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C