What the vulnerability does
01Description
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Explanation of Vulnerability in Simple Terms
Contact Form by Supsystic versions before 1.10.0 contain an authentication bypass vulnerability. An attacker can access or modify form data and settings without logging in. The vulnerability exists in an alternate authentication path that does not properly validate user credentials. Update to version 1.10.0 or later to fix this issue.
What an attacker can do
Access and modify contact form data and settings without authentication.
Potential impact on your site
Attackers can read, modify, or delete form submissions and plugin settings without a password.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities