CVE-2024-1130: NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_read()
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the setread() function in all versions up to, and including, 8.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark records as read.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1130?
The severity of CVE-2024-1130 is considered high due to the potential for unauthorized access by authenticated attackers.
How do I fix CVE-2024-1130?
To fix CVE-2024-1130, update the NEX-Forms – Ultimate Form Builder plugin to version 8.5.7 or later.
Who is impacted by CVE-2024-1130?
Authenticated users with subscriber privileges on WordPress sites using versions of NEX-Forms up to 8.5.6 are impacted by CVE-2024-1130.
What is the nature of the vulnerability in CVE-2024-1130?
CVE-2024-1130 is a vulnerability caused by a missing capability check in the set_read() function, allowing unauthorized access.
What versions of NEX-Forms are affected by CVE-2024-1130?
All versions of NEX-Forms – Ultimate Form Builder up to and including 8.5.6 are affected by CVE-2024-1130.