CVE-2024-10593: WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the processadminui function. This makes it possible for unauthenticated attackers to delete WPForm logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10593?
CVE-2024-10593 is classified as a moderate severity vulnerability.
How do I fix CVE-2024-10593?
To fix CVE-2024-10593, update the WPForms plugin to version 1.9.1.7 or later.
What types of attacks can CVE-2024-10593 lead to?
CVE-2024-10593 can lead to Cross-Site Request Forgery (CSRF) attacks.
Which versions are affected by CVE-2024-10593?
All versions of the WPForms plugin up to and including 1.9.1.6 are affected by CVE-2024-10593.
What is the cause of CVE-2024-10593?
CVE-2024-10593 is caused by missing or incorrect nonce validation in the WPForms plugin.