CVE-2022-23180

CVE-2022-23180: Contact Form & Lead Form Elementor Builder Plugin < 1.7.4 - Multiple Subscriber+ Settings Update

Vendor Unknown
Product Contact Form & Lead Form Elementor Builder
Published January 16, 2024
Last update June 16, 2025

CVSS base score

What the vulnerability does

01Description

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings

Key dates

02Disclosure timeline

January 16, 2024 CVE published
June 16, 2025 Record updated