Missing Authorization Vulnerability in CubeWP Forms by CubeWP
CVE-2024-51651
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 January 2025
What is CVE-2024-51651?
The CubeWP Forms – All-in-One Form Builder is susceptible to a missing authorization vulnerability, allowing unauthorized users to exploit incorrectly configured access control security levels. This issue affects all versions up to and including 1.1.5, which could lead to unintended access to sensitive features or data. Proper validation and enforcement of user permissions are essential to mitigate this risk.
Affected Version(s)
CubeWP Forms – All-in-One Form Builder <= 1.1.5