First published: Sat Feb 01 2025(Updated: )
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user submitted forms.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Contact Forms by Cimatti | <=1.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12184 has a high severity as it allows unauthorized access to data for unauthenticated attackers.
To fix CVE-2024-12184, update the WordPress Contact Forms by Cimatti plugin to version 1.9.5 or later.
All users of the WordPress Contact Forms by Cimatti plugin on version 1.9.4 or earlier are affected by CVE-2024-12184.
Yes, CVE-2024-12184 can be exploited remotely by unauthenticated attackers.
The vulnerability in CVE-2024-12184 is due to a missing capability check in the accua_forms_download_submitted_file() function.