Unauthorized Access to Functionality in Responsive Contact Form Builder & Lead Generation Plugin Due to Missing Capability Check
CVE-2024-1416
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 2 May 2024
What is CVE-2024-1416?
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions.
Affected Version(s)
Responsive Contact Form Builder & Lead Generation Plugin * <= 1.8.9