VYPR
Medium severity5.3NVD Advisory· Published Nov 6, 2024· Updated Jun 17, 2026No known patch

CVE-2024-6626

CVE-2024-6626

Description

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in all versions up to, and including, 2.9.9.9. This makes it possible for unauthenticated attackers to view form submissions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:theinnovs:eleforms:*:*:*:*:*:wordpress:*:*
    Range: <=2.9.9.9
  • WordPress/EleFormsllm-fuzzy2 versions
    <=2.9.9.9+ 1 more
    • (no CPE)range: <=2.9.9.9
    • (no CPE)
  • cscode/EleForms – All In One Form Integration including DB for Elementorv5
    Range: 0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.