What the vulnerability does
01Description
Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plugin – Gutenberg Forms: from n/a through 2.2.8.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plugin – Gutenberg Forms: from n/a through 2.2.8.3.
Explanation of Vulnerability in Simple Terms
The Gutenberg Forms plugin for WordPress does not properly check user permissions before allowing modifications to form data. A logged-in user with low privileges can alter forms they should not have access to, including changing form settings, fields, or submissions. This affects versions up to 2.2.8.3. Site administrators should update the plugin immediately.
What an attacker can do
A low-privilege user can modify forms and their data without proper authorization.
Potential impact on your site
Form data and settings can be altered by unauthorized users, risking data integrity and form functionality.
Conditions required to exploit
Attacker must have a WordPress user account with at least low-level privileges.
Key dates
External resources
Related vulnerabilities