First published: Tue Jun 13 2023(Updated: )
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cimatti WordPress Contact Forms | <=1.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2563 is a vulnerability in the WordPress Contact Forms by Cimatti plugin for WordPress that allows for Cross-Site Request Forgery attacks.
The severity of CVE-2023-2563 is medium, with a CVSS score of 4.3.
Unauthenticated attackers can exploit CVE-2023-2563 by performing Cross-Site Request Forgery attacks.
Versions up to and including 1.5.7 of the Contact Forms by Cimatti plugin for WordPress are affected by CVE-2023-2563.
To fix CVE-2023-2563, it is recommended to update the Contact Forms by Cimatti plugin to a version higher than 1.5.7.