Lucene search

K
cvelistWPScanCVELIST:CVE-2022-23180
HistoryJan 16, 2024 - 3:52 p.m.

CVE-2022-23180 Contact Form & Lead Form Elementor Builder Plugin < 1.7.4 - Multiple Subscriber+ Settings Update

2024-01-1615:52:09
WPScan
www.cve.org
3
wordpress
plugin
security vulnerability
authentication bypass
settings update

AI Score

4.9

Confidence

High

EPSS

0

Percentile

14.0%

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn’t have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Contact Form & Lead Form Elementor Builder",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "1.7.4"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

AI Score

4.9

Confidence

High

EPSS

0

Percentile

14.0%

Related for CVELIST:CVE-2022-23180