VYPR
Unrated severityNVD Advisory· Published Apr 15, 2024· Updated Aug 9, 2024

Smart Forms < 2.6.94 - Subscriber+ Edit Entries via Broken Access Control

CVE-2024-1307

Description

The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perform unauthorized actions

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.