Unrated severityNVD Advisory· Published Nov 6, 2024· Updated Apr 8, 2026
EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.9 - Missing Authorization
CVE-2024-6626
Description
The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in all versions up to, and including, 2.9.9.9. This makes it possible for unauthenticated attackers to view form submissions.
Affected products
2- Range: <=2.9.9.9
- cscode/EleForms – All In One Form Integration including DB for Elementorv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/export_csv.phpmitre
- plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/wp-ajax.phpmitre
- plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/wp-ajax.phpmitre
- www.wordfence.com/threat-intel/vulnerabilities/id/eccea504-b8b9-46d3-b9fd-ae893528e521mitre
News mentions
0No linked articles in our index yet.