First published: Thu Oct 31 2024(Updated: )
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the submit_quizzes() function due to missing validation on the 'entry_id' user controlled key. This makes it possible for unauthenticated attackers to modify other user's quiz submissions.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forminator Forms | <1.36.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9700 is considered a medium severity vulnerability due to its potential impact on user data through insecure direct object references.
To fix CVE-2024-9700, update the Forminator Forms plugin to the latest version, specifically 1.36.1 or higher.
All versions of Forminator Forms up to and including 1.36.0 are affected by CVE-2024-9700.
CVE-2024-9700 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
CVE-2024-9700 impacts the submit_quizzes() function of the Forminator Forms plugin, allowing unauthorized access to user-controlled 'entry_id' parameters.