Smart Forms – when you need more than just a contact form <= 2.1.0 - Missing Authorization
2014-11-06 00:00
Kacper SzurekStrategic Overview
StatusPatched in 2.1.1
Affected PluginSmart Forms – when you need more than just a contact form
Affected Version
<= 2.1.0CVSS7.2High
CVE
CVE-2014-8803Vulnerability Overview
The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the rednao_smart_forms_save_form_values function in versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to edit forms, including entering stored cross-site scripting, as output is not properly escaped.
Technical Analysis
REMEDIATION: Update to version 2.1.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C