CVE-2023-2517: Metform Elementor Contact Form Builder <= 3.3.2 - Cross-Site Request Forgery via permalink_setup
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on the permalinksetup function. This makes it possible for unauthenticated attackers to change the permalink structure via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. While nonce verification is implemented, verification only takes place when a nonce is provided.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-2517?
CVE-2023-2517 is a vulnerability in the Metform Elementor Contact Form Builder plugin for WordPress that allows unauthenticated attackers to perform Cross-Site Request Forgery attacks.
What is the severity of CVE-2023-2517?
CVE-2023-2517 has a severity level of medium.
Which versions of Metform Elementor Contact Form Builder are affected by CVE-2023-2517?
Versions up to and including 3.3.2 of Metform Elementor Contact Form Builder are affected by CVE-2023-2517.
How can an attacker exploit CVE-2023-2517?
An attacker can exploit CVE-2023-2517 by tricking a user into visiting a specially crafted webpage or by enticing them to click on a malicious link.
Is there a fix available for CVE-2023-2517?
Yes, the fix for CVE-2023-2517 is to update to a version of Metform Elementor Contact Form Builder that is greater than 3.3.2.