CVE-2022-47166: WordPress Void Contact Form 7 Widget For Elementor Page Builder Plugin <= 2.1.1 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47166?
CVE-2022-47166 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2022-47166?
To fix CVE-2022-47166, update the Void Contact Form 7 Widget For Elementor Page Builder plugin to version 2.2 or later.
Which versions are affected by CVE-2022-47166?
Versions of the Void Contact Form 7 Widget For Elementor Page Builder plugin up to and including 2.1.1 are affected by CVE-2022-47166.
What is a Cross-Site Request Forgery (CSRF) vulnerability like CVE-2022-47166?
A Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to trick a user into executing unwanted actions on a web application in which they are authenticated.
What are the consequences of CVE-2022-47166 if exploited?
If exploited, CVE-2022-47166 could allow unauthorized actions to be performed on behalf of an authenticated user.