CVE-2024-6626

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in all versions up to, and including, 2.9.9.9. This makes it possible for unauthenticated attackers to view form submissions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:theinnovs:eleforms:*:*:*:*:*:wordpress:*:*

History

08 Nov 2024, 21:18

Type Values Removed Values Added
First Time Theinnovs
Theinnovs eleforms
References () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/export_csv.php#L20 - () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/export_csv.php#L20 - Product
References () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/wp-ajax.php#L147 - () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/wp-ajax.php#L147 - Product
References () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/wp-ajax.php#L7 - () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/wp-ajax.php#L7 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/eccea504-b8b9-46d3-b9fd-ae893528e521?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/eccea504-b8b9-46d3-b9fd-ae893528e521?source=cve - Third Party Advisory
CPE cpe:2.3:a:theinnovs:eleforms:*:*:*:*:*:wordpress:*:*

06 Nov 2024, 18:17

Type Values Removed Values Added
Summary
  • (es) El complemento EleForms – All In One Form Integration including DB for Elementor para WordPress es vulnerable al acceso no autorizado a los datos debido a la falta de comprobación de capacidad en varias funciones en todas las versiones hasta la 2.9.9.9 incluida. Esto permite que atacantes no autenticados vean los envíos de formularios.

06 Nov 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-06 07:15

Updated : 2024-11-08 21:18


NVD link : CVE-2024-6626

Mitre link : CVE-2024-6626

CVE.ORG link : CVE-2024-6626


JSON object : View

Products Affected

theinnovs

  • eleforms
CWE
CWE-862

Missing Authorization