Medium severity4.3NVD Advisory· Published May 2, 2024· Updated Apr 15, 2026
CVE-2024-1416
CVE-2024-1416
Description
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- plugins.trac.wordpress.org/browser/lead-form-builder/trunk/inc/ajax-functions.phpnvd
- plugins.trac.wordpress.org/browser/lead-form-builder/trunk/inc/ajax-functions.phpnvd
- plugins.trac.wordpress.org/browser/lead-form-builder/trunk/inc/lf-install.phpnvd
- plugins.trac.wordpress.org/changeset/3068835nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/d087957c-0dd5-46a9-a6bc-85f2f79f43bdnvd
News mentions
0No linked articles in our index yet.