First published: Mon Jun 03 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks. Integration for Contact Form 7 and Constant Contact.This issue affects Integration for Contact Form 7 and Constant Contact: from n/a through 1.1.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Integration For Constant Contact and Contact Form 7 | <=1.1.5 | |
Crmperks Integration For Constant Contact And Contact Form 7, Wpforms, Elementor, Ninja | <=1.1.5 | |
WPForms | <=1.1.5 | |
Elementor | <=1.1.5 | |
Ninja Forms | <=1.1.5 |
Update to 1.1.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35632 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to unauthorized actions being performed on behalf of the user.
To fix CVE-2024-35632, update the Integration for Contact Form 7 and Constant Contact plugin to the latest version beyond 1.1.5.
CVE-2024-35632 affects versions up to and including 1.1.5 of the Integration for Contact Form 7 and Constant Contact plugin.
Users of the CRM Perks Integration for Contact Form 7 and Constant Contact plugin, including WordPress users utilizing WPForms, Elementor, or Ninja Forms, are affected by CVE-2024-35632.
CVE-2024-35632 is a Cross-Site Request Forgery (CSRF) vulnerability that enables attackers to trick users into performing actions without their consent.