The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in all versions up to, and including, 2.9.9.9. This makes it possible for unauthenticated attackers to view form submissions.
References
Configurations
History
08 Nov 2024, 21:18
Type | Values Removed | Values Added |
---|---|---|
First Time |
Theinnovs
Theinnovs eleforms |
|
References | () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/export_csv.php#L20 - Product | |
References | () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/wp-ajax.php#L147 - Product | |
References | () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/wp-ajax.php#L7 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/eccea504-b8b9-46d3-b9fd-ae893528e521?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:theinnovs:eleforms:*:*:*:*:*:wordpress:*:* |
06 Nov 2024, 18:17
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
06 Nov 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-06 07:15
Updated : 2024-11-08 21:18
NVD link : CVE-2024-6626
Mitre link : CVE-2024-6626
CVE.ORG link : CVE-2024-6626
JSON object : View
Products Affected
theinnovs
- eleforms
CWE
CWE-862
Missing Authorization