ZeroHour

CVE-2022-23180

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p43
Published
()
Modified
Description

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings

Vendors
themehunk
Products
contact form \& lead form elementor builder
Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.