CVE-2023-52214: WordPress Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.3 - Broken Access Control vulnerability
Published Mar 26, 2024
·Updated
Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: from n/a through 2.3.
Affected Software
3 affected components
voidCoders Void Contact Form 7 Widget For Elementor Page Builder<=2.3
WordPress Void Contact Form 7 Widget For Elementor Page Builder<=2.3
voidCoders Void Contact Form 7 Widget For Elementor Page Builder Wordpress<2.4
Remediation
Information
Update to 2.4 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52214?
CVE-2023-52214 is classified as a Missing Authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2023-52214?
To fix CVE-2023-52214, update the Void Contact Form 7 Widget For Elementor Page Builder to version 2.4 or higher.
3
Which versions are affected by CVE-2023-52214?
CVE-2023-52214 affects all versions of the Void Contact Form 7 Widget For Elementor Page Builder up to and including version 2.3.
4
What kind of issues can CVE-2023-52214 cause?
CVE-2023-52214 can allow unauthorized users to perform actions they shouldn't be able to, leading to potential data breaches.
5
Who is the vendor for the product affected by CVE-2023-52214?
The vendor for the affected product is VoidCoders.