CVE-2023-6325: RomethemeForm For Elementor <= 1.1.5 - Missing Authorization via export_entries, rtformnewform, and rtformupdate
The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the exportentries, rtformnewform, and rtformupdate functions in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to export arbitrary form submissions, create new forms, or update any post title or certain metadata.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6325?
CVE-2023-6325 is considered a critical vulnerability due to unauthorized access and data modification.
How do I fix CVE-2023-6325?
To fix CVE-2023-6325, update the RomethemeForm For Elementor plugin to version 1.1.6 or later.
Which versions are affected by CVE-2023-6325?
CVE-2023-6325 affects all versions of the RomethemeForm For Elementor plugin up to and including 1.1.5.
What are the consequences of CVE-2023-6325?
The consequences of CVE-2023-6325 include unauthorized access and potential modification of user data.
What functions are vulnerable in CVE-2023-6325?
The vulnerable functions in CVE-2023-6325 include export_entries, rtformnewform, and rtformupdate.