CVE-2024-1645: Mollie Forms <= 2.6.3 - Missing Authorization
The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportRegistrations function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with subscriber access or higher, to export payment data collected by this plugin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1645?
CVE-2024-1645 has a medium severity rating due to the potential for unauthorized data access.
How do I fix CVE-2024-1645?
To fix CVE-2024-1645, update the Mollie Forms plugin for WordPress to version 2.6.4 or later.
Who is affected by CVE-2024-1645?
Authenticated users with subscriber access or higher are affected by CVE-2024-1645.
What versions of the Mollie Forms plugin are vulnerable to CVE-2024-1645?
All versions of the Mollie Forms plugin for WordPress up to and including 2.6.3 are vulnerable to CVE-2024-1645.
What function in the Mollie Forms plugin contains the vulnerability CVE-2024-1645?
The vulnerability CVE-2024-1645 exists in the exportRegistrations function due to a missing capability check.