1 results (0.004 seconds)

CVSS: 4.3EPSS: %CPEs: 1EXPL: 0

The Icegram Collect – Easy Form, Lead Collection and Subscription plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the disconnect_campaignmonitor() function, along with a few others, in versions up to, and including, 1.3.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify plugin settings. • CWE-862: Missing Authorization •