Unauthorized Access Vulnerability in The Forminator Forms Plugin for WordPress
CVE-2024-10402
7.5HIGH
Key Information:
- Vendor
- WPmudev
- Status
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder
- Vendor
- CVE Published:
- 26 October 2024
Summary
The Forminator Forms plugin for WordPress encompasses a security flaw that allows authenticated users with Contributor-level access or higher to bypass essential capability checks. This vulnerability exists in all versions through 1.35.1, potentially permitting attackers to create, edit, and manipulate forms. Notably, this could lead to unauthorized updates of default registration roles, specifically enabling Users to be assigned as Administrators, posing significant risks to data integrity and user access controls.
Affected Version(s)
Forminator Forms – Contact Form, Payment Form & Custom Form Builder * <= 1.35.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
wesley