First published: Mon Apr 15 2024(Updated: )
The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perform unauthorized actions
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Smart Forms | <2.6.94 | |
Baal Smart Forms | <2.6.94 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1307 has been classified with a high severity due to improper authorization that allows unauthorized actions by low-level users.
To fix CVE-2024-1307, update the Smart Forms WordPress plugin to version 2.6.94 or later.
Users of the Smart Forms WordPress plugin before version 2.6.94 are affected by CVE-2024-1307.
CVE-2024-1307 allows users with subscriber roles to perform actions that should be restricted to higher privilege users.
Yes, it is safe to use the Smart Forms plugin after updating to version 2.6.94 or later to address CVE-2024-1307.