What the vulnerability does
01Description
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8.
Explanation of Vulnerability in Simple Terms
WP Libre Form 2 through version 2.0.8 exposes sensitive information to unauthenticated attackers over the network. The plugin fails to properly restrict access to data, allowing attackers to read and modify information without authentication. This affects all installations running the vulnerable version.
What an attacker can do
Read and modify form data and other sensitive information without logging in.
Potential impact on your site
Form submissions and other plugin data may be exposed to or modified by unauthorized visitors.
Conditions required to exploit
None. The attacker needs only network access to the WordPress site.
Key dates
External resources
Related vulnerabilities