What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Forms by CaptainForm – Form Builder for WordPress plugin <= 2.5.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Forms by CaptainForm – Form Builder for WordPress plugin <= 2.5.3 versions.
Explanation of Vulnerability in Simple Terms
Forms by CaptainForm contains a cross-site request forgery (CSRF) vulnerability affecting versions up to 2.5.3. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the form builder without the admin's knowledge or consent. This could allow modification or deletion of forms, or changes to plugin settings.
What an attacker can do
Trick a logged-in admin into performing unwanted actions on forms or plugin settings via a malicious webpage.
Potential impact on your site
Forms could be modified, deleted, or settings changed without admin authorization if an admin visits a malicious link.
Conditions required to exploit
Admin must be logged in and visit an attacker-controlled webpage; no special plugin configuration required.
Key dates
External resources
Related vulnerabilities