CVE-2024-56276: WordPress WPForms Lite plugin <= 1.9.2.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through <= 1.9.2.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56276?
CVE-2024-56276 is classified as a missing authorization vulnerability that can lead to unauthorized access due to incorrectly configured access control levels.
How do I fix CVE-2024-56276?
To fix CVE-2024-56276, update the WPForms Contact Form or WPForms Lite plugin to the latest version beyond 1.9.2.2.
Which versions are affected by CVE-2024-56276?
CVE-2024-56276 affects WPForms Contact Form and WPForms Lite versions up to and including 1.9.2.2.
What impact does CVE-2024-56276 have on my website?
Exploiting CVE-2024-56276 could enable attackers to bypass access controls and potentially access or manipulate sensitive information.
Is CVE-2024-56276 specific to a certain plugin?
Yes, CVE-2024-56276 specifically affects the WPForms Contact Form and WPForms Lite plugins.