First published: Fri Jun 09 2023(Updated: )
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about any standard form field of any form submission.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpmet Metform Elementor Contact Form Builder | <=3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-0694.
The severity of CVE-2023-0694 is medium (4.3).
CVE-2023-0694 allows authenticated attackers with subscriber-level capabilities or above to obtain sensitive information about any standard form fields.
Versions up to and including 3.3.1 of Metform Elementor Contact Form Builder for WordPress are affected by CVE-2023-0694.
Yes, you can find references for CVE-2023-0694 at the following URLs: [Wordfence](https://www.wordfence.com/threat-intel/vulnerabilities/id/1a8b194c-371f-4adc-98fa-8f4e47a38ee7?source=cve), [Trac WordPress](https://plugins.trac.wordpress.org/browser/metform/trunk/base/shortcode.php?rev=2845078), [Changeset](https://plugins.trac.wordpress.org/changeset/2910040/).