CVE-2023-25035: WordPress Quick Contact Form plugin <= 8.0.3.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Contact Form: from n/a through <= 8.0.3.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25035?
CVE-2023-25035 is classified as a Missing Authorization vulnerability that can be exploited due to incorrectly configured access control security levels.
How do I fix CVE-2023-25035?
To fix CVE-2023-25035, ensure that access control settings are properly configured in the Fullworks Quick Contact Form plugin.
Which versions are affected by CVE-2023-25035?
CVE-2023-25035 affects all versions of the Fullworks Quick Contact Form plugin up to and including version 8.0.3.1.
What is the impact of CVE-2023-25035?
The impact of CVE-2023-25035 may allow unauthorized access, potentially leading to data exposure or manipulation.
Is there a patch available for CVE-2023-25035?
Yes, the latest updates and patches for the Quick Contact Form plugin should address the vulnerabilities associated with CVE-2023-25035.