Unrated severityNVD Advisory· Published Mar 7, 2022· Updated Aug 2, 2024
Smart Forms < 2.6.71 - Subscriber+ Form Data Download
CVE-2022-0163
Description
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/2b6b0731-4515-498a-82bd-d416f5885268mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.