Access Control Flaw in Porthas Inc. MightyForms Plugin
CVE-2024-56002
6.4MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 31 December 2024
Summary
The vulnerability within Porthas Inc. MightyForms plugin exemplifies a missing authorization flaw that arises from incorrectly configured access control security levels. This issue poses a risk by allowing unauthorized users to exploit the contact form and survey functionalities, potentially accessing sensitive data or performing actions without proper permissions. The problem is present in the MightyForms plugin, specifically in versions prior to 1.3.9, necessitating prompt attention to security configurations to safeguard user information.
Affected Version(s)
Contact Form, Survey & Form Builder – MightyForms <= 1.3.9
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)