First published: Fri May 17 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Salesforce.This issue affects Integration for Contact Form 7 and Salesforce: from n/a through 1.3.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Integration For Salesforce and Contact Form 7 | <=1.3.9 | |
WordPress Integration For Salesforce and Contact Form 7 | <=1.3.9 | |
WPForms | <=1.3.9 | |
Elementor | <=1.3.9 | |
Formidable Forms by Strategy11 | <=1.3.9 | |
Ninja Forms | <=1.3.9 |
Update to 1.4.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34755 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2024-34755, update the CRM Perks Integration for Contact Form 7 and Salesforce plugin to version 1.4 or higher.
CVE-2024-34755 affects versions of CRM Perks Integration for Contact Form 7 and Salesforce from n/a through 1.3.9.
CVE-2024-34755 impacts CRM Perks Integration for Contact Form 7 and Salesforce, WPForms, Elementor, Formidable, and Ninja Forms.
An attacker exploiting CVE-2024-34755 can perform unauthorized actions on behalf of users without their consent.