Access Control Flaw in Porthas Inc. MightyForms Plugin
CVE-2024-56002
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2024
What is CVE-2024-56002?
The vulnerability within Porthas Inc. MightyForms plugin exemplifies a missing authorization flaw that arises from incorrectly configured access control security levels. This issue poses a risk by allowing unauthorized users to exploit the contact form and survey functionalities, potentially accessing sensitive data or performing actions without proper permissions. The problem is present in the MightyForms plugin, specifically in versions prior to 1.3.9, necessitating prompt attention to security configurations to safeguard user information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contact Form, Survey & Form Builder β MightyForms <= 1.3.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved