CVE-2024-11205: WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpformsisadminpage' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11205?
The severity of CVE-2024-11205 is considered to be critical due to its potential for unauthorized data modification.
How do I fix CVE-2024-11205?
To fix CVE-2024-11205, update the WPForms plugin to a version later than 1.9.2.1.
What versions of WPForms are affected by CVE-2024-11205?
CVE-2024-11205 affects WPForms versions from 1.8.4 up to and including 1.9.2.1.
Who can exploit CVE-2024-11205?
Authenticated attackers with subscriber-level access can exploit CVE-2024-11205 due to the missing capability check.
What impact does CVE-2024-11205 have on a WordPress site?
CVE-2024-11205 can lead to unauthorized modification of data, impacting the integrity of forms and user information on a WordPress site.