What the vulnerability does
01Description
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
Explanation of Vulnerability in Simple Terms
Contact Form by WPForms versions up to 1.10.0.4 lack proper authorization checks, allowing unauthenticated attackers to modify form data or settings. An attacker can send a crafted network request to alter forms without needing to log in or interact with a user. Site owners should update immediately to prevent unauthorized changes to contact forms and potential data loss.
What an attacker can do
Modify or delete contact forms and their settings without logging in.
Potential impact on your site
Contact forms can be altered or deleted by anyone on the internet, disrupting lead capture and potentially exposing form data.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities