Access Control Flaw in Porthas Inc. MightyForms Plugin
CVE-2024-56002

6.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
31 December 2024

Summary

The vulnerability within Porthas Inc. MightyForms plugin exemplifies a missing authorization flaw that arises from incorrectly configured access control security levels. This issue poses a risk by allowing unauthorized users to exploit the contact form and survey functionalities, potentially accessing sensitive data or performing actions without proper permissions. The problem is present in the MightyForms plugin, specifically in versions prior to 1.3.9, necessitating prompt attention to security configurations to safeguard user information.

Affected Version(s)

Contact Form, Survey & Form Builder – MightyForms <= 1.3.9

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.