CVE-2024-12190
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder <= 2.17.3 - Missing Authorization to Authenticated (Subscriber+) Form Submission Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bitform-form-entry-edit endpoint in all versions up to, and including, 2.17.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view all form submissions from other users.
Contact Form de Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form y Custom Contact Form builder para WordPress es vulnerable al acceso no autorizado a los datos debido a una falta de verificación de capacidad en el endpoint bitform-form-entry-edit en todas las versiones hasta la 2.17.3 incluida. Esto hace posible que los atacantes autenticados, con acceso de nivel de suscriptor y superior, vean todos los envíos de formularios de otros usuarios.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-12-04 CVE Reserved
- 2024-12-24 CVE Published
- 2024-12-27 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bitpressadmin Search vendor "Bitpressadmin" | Contact Form Search vendor "Bitpressadmin" for product "Contact Form" | <= 2.17.3 Search vendor "Bitpressadmin" for product "Contact Form" and version " <= 2.17.3" | en |
Affected
|