Authorization Flaw in Bit Apps Bit Form Pro by Bit Apps
CVE-2024-43250

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 August 2024

What is CVE-2024-43250?

An incorrect authorization vulnerability in Bit Apps' Bit Form Pro allows users to access functionality not properly constrained by access control lists (ACLs). This security flaw specifically impacts versions of Bit Form Pro from n/a through 2.6.4, potentially exposing sensitive settings and data to unauthorized users. It is crucial for users to review their security configurations and update their systems to mitigate risks associated with this vulnerability.

Affected Version(s)

Bit Form Pro <= 2.6.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.