CVE-2024-1400: Mollie Forms <= 2.6.3 - Missing Authorization to Arbitrary Post Duplication
The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability check on the duplicateForm function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with subscriber access or higher, to duplicate arbitrary posts and pages.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1400?
The severity of CVE-2024-1400 is considered important due to the potential for unauthorized duplication of posts or pages.
How do I fix CVE-2024-1400?
To fix CVE-2024-1400, update the Mollie Forms plugin for WordPress to version 2.6.4 or higher.
Who is affected by CVE-2024-1400?
CVE-2024-1400 affects users of the Mollie Forms plugin for WordPress with versions up to and including 2.6.3.
What functionality is compromised in CVE-2024-1400?
CVE-2024-1400 compromises the ability to securely duplicate forms, allowing unauthorized users to duplicate content.
Which versions of the Mollie Forms plugin are vulnerable to CVE-2024-1400?
All versions of the Mollie Forms plugin for WordPress up to and including 2.6.3 are vulnerable to CVE-2024-1400.