CVE-2024-9629: Contact Form 7 + Telegram <= 0.8.5 - Missing Authorization to Authenticated (Subscriber+) Subscription Approve/Pause/Refuse
The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'wpcf7Telegram::ajax' function in versions up to, and including, 0.8.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to approve, pause and refuse subscriptions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9629?
CVE-2024-9629 is classified as a high severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2024-9629?
To fix CVE-2024-9629, update the Contact Form 7 + Telegram plugin to version 0.8.6 or later.
Who is affected by CVE-2024-9629?
Users of the Contact Form 7 + Telegram plugin for WordPress, especially those using versions up to 0.8.5, are affected by CVE-2024-9629.
What type of attacks can occur due to CVE-2024-9629?
CVE-2024-9629 allows authenticated attackers to perform unauthorized modifications of data through the plugin.
When was CVE-2024-9629 published?
CVE-2024-9629 was published in 2024, drawing attention to a significant vulnerability in a widely used WordPress plugin.