CVE-2024-3649
Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product information, and quantities for purchases made via the Stripe payment integration.
El complemento Contact Form by WPForms – Drag & Drop Form Builder para WordPress es vulnerable a la manipulación de precios en versiones hasta la 1.8.7.2 incluida. Esto se debe a la falta de controles sobre varios parámetros del producto. Esto hace posible que atacantes no autenticados manipulen precios, información de productos y cantidades de compras realizadas a través de la integración de pagos de Stripe.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-04-10 CVE Reserved
- 2024-05-01 CVE Published
- 2024-05-03 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-472: External Control of Assumed-Immutable Web Parameter
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Smub Search vendor "Smub" | Contact Form Search vendor "Smub" for product "Contact Form" | <= 1.8.7.2 Search vendor "Smub" for product "Contact Form" and version " <= 1.8.7.2" | en |
Affected
|