CVE-2024-12190: Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder <= 2.17.3 - Missing Authorization to Authenticated (Subscriber+) Form Submission Disclosure
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bitform-form-entry-edit endpoint in all versions up to, and including, 2.17.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view all form submissions from other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12190?
CVE-2024-12190 is deemed to have a medium severity due to unauthorized access of data.
How do I fix CVE-2024-12190?
To fix CVE-2024-12190, update the Bit Form Contact Form plugin to version 2.17.4 or later.
What versions are affected by CVE-2024-12190?
CVE-2024-12190 affects all versions of the Bit Form Contact Form plugin up to and including 2.17.3.
Is particular data exposed due to CVE-2024-12190?
Yes, CVE-2024-12190 allows unauthorized access to sensitive form entry data.
Who is the vendor of the affected software for CVE-2024-12190?
The vendor of the affected software for CVE-2024-12190 is Bit Form.