What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.
Explanation of Vulnerability in Simple Terms
Contact Form by WPForms versions up to 1.10.0.2 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unauthorized actions on the form plugin without the admin's knowledge or consent. This could allow modification of form settings, deletion of forms, or other administrative changes.
What an attacker can do
Perform unauthorized actions on WPForms forms by tricking an admin into visiting a malicious webpage.
Potential impact on your site
Forms could be modified, deleted, or misconfigured without your knowledge if an admin visits a malicious link.
Conditions required to exploit
Admin must be logged in and visit attacker-controlled webpage; no special privileges or direct site access needed.
Key dates
External resources
Related vulnerabilities