CVE-2023-1843: Metform Elementor Contact Form Builder <= 3.3.0 - Missing Authorization
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability check on the permalinksetup function in versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to change the permalink structure.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-1843?
CVE-2023-1843 refers to a vulnerability in the Metform Elementor Contact Form Builder plugin for WordPress that allows unauthorized permalink structure updates.
What is the severity of CVE-2023-1843?
CVE-2023-1843 has a severity rating of medium, with a severity value of 5.3.
How does CVE-2023-1843 affect the Metform Elementor Contact Form Builder plugin?
CVE-2023-1843 affects the Metform Elementor Contact Form Builder plugin for WordPress up to version 3.3.0.
How can unauthenticated attackers exploit CVE-2023-1843?
Unauthenticated attackers can exploit CVE-2023-1843 to change the permalink structure without proper authorization.
Is there a fix available for CVE-2023-1843?
To fix CVE-2023-1843, it is recommended to update the Metform Elementor Contact Form Builder plugin to a version higher than 3.3.0.