CVE-2023-0691: Metform Elementor Contact Form Builder <= 3.3.1 - Authenticated (Subscriber+) Information Disclosure via mf_last_name shortcode
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mflastname' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, specifically the submitter's last name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-0691?
CVE-2023-0691 is a vulnerability that exists in the Metform Elementor Contact Form Builder for WordPress.
How can an attacker exploit CVE-2023-0691?
An attacker with subscriber-level capabilities or above can exploit CVE-2023-0691 to obtain sensitive information using the 'mf_last_name' shortcode.
What is the severity of CVE-2023-0691?
CVE-2023-0691 has a severity rating of 4.3, which is considered medium.
Which versions of Metform Elementor Contact Form Builder are affected by CVE-2023-0691?
Versions up to and including 3.3.1 of Metform Elementor Contact Form Builder for WordPress are affected by CVE-2023-0691.
Is there a fix available for CVE-2023-0691?
Yes, updating to a version beyond 3.3.1 of Metform Elementor Contact Form Builder for WordPress will fix CVE-2023-0691.