CVE-2024-1640: Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form <= 2.10.1 - Unauthenticated Insecure Direct Object Reference to Form Submission Alteration
The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitformsupdateformentry AJAX action in all versions up to, and including, 2.10.1. This makes it possible for unauthenticated attackers to modify form submissions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1640?
CVE-2024-1640 has a high severity rating due to its potential for unauthorized data modification.
How do I fix CVE-2024-1640?
To fix CVE-2024-1640, update the Contact Form Builder Plugin to version 2.10.3 or later.
Which versions are affected by CVE-2024-1640?
CVE-2024-1640 affects all versions of the Contact Form Builder Plugin up to and including 2.10.2.
What impact does CVE-2024-1640 have on WordPress sites?
CVE-2024-1640 allows unauthorized users to modify form entries, compromising data integrity on affected WordPress sites.
Is user authentication affected by CVE-2024-1640?
Yes, CVE-2024-1640 is caused by insufficient user validation during the bitforms_update_form_entry AJAX action.