CVE-2022-1442
Metform Elementor Contact Form Builder <= 2.1.3 - Sensitive Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.
El plugin Metform para WordPress es vulnerable a una divulgación de información confidencial debido a un control de acceso inapropiado en el archivo ~/core/forms/action.php que puede ser aprovechado por un atacante no autenticado para visualizar todas las claves y secretos de las API de terceros integradas como la de PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA y muchas más, en versiones hasta la 2.1.3 incluyéndola
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-23 CVE Reserved
- 2022-04-23 CVE Published
- 2023-08-03 First Exploit
- 2024-07-03 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/threat-intel/vulnerabilities/id/04a46249-b5b2-4082-b520-cdc4a1370bb1?source=cve | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/RandomRobbieBF/CVE-2022-1442 | 2023-08-03 | |
https://gist.github.com/Xib3rR4dAr/6e6c6e5fa1f8818058c7f03de1eda6bf | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2711944/metform/trunk/core/forms/action.php | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpmet Search vendor "Wpmet" | Metform Elementor Contact Form Builder Search vendor "Wpmet" for product "Metform Elementor Contact Form Builder" | < 2.1.4 Search vendor "Wpmet" for product "Metform Elementor Contact Form Builder" and version " < 2.1.4" | wordpress |
Affected
|