Lucene search

K
wpvulndbWpvulndbWPVDB-ID:CB513C20-D37D-4785-A10A-D8BCAFC8456E
HistoryNov 29, 2023 - 12:00 a.m.

Contact Form to Any API < 1.1.7 - Subscriber+ API Entry Record Deletion

2023-11-2900:00:00
wpscan.com
18
plugin
authorization
deletion
security
user

9.3 High

AI Score

Confidence

High

Description The plugin does not have authorisation check when deleting CF7 API entry records, which could allow any authenticated users, such as subscriber to delete them

CPENameOperatorVersion
eq1.1.7

9.3 High

AI Score

Confidence

High

Related for WPVDB-ID:CB513C20-D37D-4785-A10A-D8BCAFC8456E