First published: Fri Jun 09 2023(Updated: )
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability check on the permalink_setup function in versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to change the permalink structure.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpmet Metform Elementor Contact Form Builder | <=3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1843 refers to a vulnerability in the Metform Elementor Contact Form Builder plugin for WordPress that allows unauthorized permalink structure updates.
CVE-2023-1843 has a severity rating of medium, with a severity value of 5.3.
CVE-2023-1843 affects the Metform Elementor Contact Form Builder plugin for WordPress up to version 3.3.0.
Unauthenticated attackers can exploit CVE-2023-1843 to change the permalink structure without proper authorization.
To fix CVE-2023-1843, it is recommended to update the Metform Elementor Contact Form Builder plugin to a version higher than 3.3.0.