CSRF Vulnerability in Contact Form 7 Connector
CVE-2024-24884
8.8HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ARI Soft Contact Form 7 Connector, allowing attackers to manipulate requests made by authenticated users without their consent. This vulnerability affects all versions of the plugin from n/a through 1.2.2, raising serious concerns for the integrity and security of user data. Attackers could exploit this flaw to perform unauthorized actions on behalf of users, compromising the confidentiality of sensitive information.
Affected Version(s)
Contact Form 7 Connector <= 1.2.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dhabaleshwar Das (Patchstack Alliance)