CVE-2024-10402: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10402?
CVE-2024-10402 is considered a high severity vulnerability due to unauthorized access by authenticated attackers.
How do I fix CVE-2024-10402?
To fix CVE-2024-10402, update the Forminator Forms plugin to version 1.36.0 or higher.
Who is affected by CVE-2024-10402?
All versions of the Forminator Forms plugin for WordPress up to and including 1.35.1 are affected by CVE-2024-10402.
What type of vulnerability is CVE-2024-10402?
CVE-2024-10402 is a security vulnerability that involves unauthorized access due to a missing capability check.
What can attackers do with CVE-2024-10402?
Authenticated attackers can exploit CVE-2024-10402 to gain unauthorized access to functions within the Forminator Forms plugin.