Medium severity4.3NVD Advisory· Published Jan 16, 2024· Updated Jun 17, 2026
CVE-2022-23180
CVE-2022-23180
Description
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:themehunk:contact_form_\&_lead_form_elementor_builder:*:*:*:*:*:wordpress:*:*Range: <1.7.4
- Range: <1.7.4
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changeset/2670484nvdPatch
- wpscan.com/vulnerability/da87358a-3a72-4cf7-a2af-a266dd9b4290/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.