Unauthenticated Attackers Can Modify Other Users' Quiz Submissions via Insecure Direct Object Reference in Forminator Forms
CVE-2024-9700
5.3MEDIUM
What is CVE-2024-9700?
The Forminator Forms plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) issue present in all versions up to and including 1.36.0. The vulnerability arises from the lack of proper validation on the 'entry_id' user-controlled key within the submit_quizzes() function. This flaw allows unauthenticated attackers to manipulate other users' quiz submissions, potentially leading to unauthorized data exposure and modifications. Website owners utilizing this plugin are advised to apply necessary security measures to mitigate the risk.