CVE-2024-33570: WordPress MetForm plugin <= 3.8.3 - Broken Access Control vulnerability
Published May 6, 2024
·Updated
Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3.
Affected Software
3 affected components
Wpmet Metform Elementor Contact Form Builder Wordpress<3.8.4
Wpmet Metform Elementor Contact Form Builder<=3.8.3
WordPress MetForm<=3.8.3
Remediation
Information
Update to 3.8.4 or a higher version.
Event History
May 6, 2024
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33570?
The severity of CVE-2024-33570 is considered critical due to its missing authorization vulnerability that could allow unauthorized access.
2
Which versions of Wpmet Metform Elementor Contact Form Builder are affected by CVE-2024-33570?
CVE-2024-33570 affects all versions of Wpmet Metform Elementor Contact Form Builder from its initial release to version 3.8.3.
3
How do I fix CVE-2024-33570?
To fix CVE-2024-33570, you should update Wpmet Metform Elementor Contact Form Builder to the latest version that addresses this vulnerability.
4
What type of vulnerability is CVE-2024-33570?
CVE-2024-33570 is classified as a missing authorization vulnerability.
5
What potential impact does CVE-2024-33570 have on my site?
CVE-2024-33570 could lead to unauthorized access, allowing attackers to manipulate form submissions and potentially access sensitive data.