CVE-2024-9700: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the submitquizzes() function due to missing validation on the 'entryid' user controlled key. This makes it possible for unauthenticated attackers to modify other user's quiz submissions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9700?
CVE-2024-9700 is considered a medium severity vulnerability due to its potential impact on user data through insecure direct object references.
How do I fix CVE-2024-9700?
To fix CVE-2024-9700, update the Forminator Forms plugin to the latest version, specifically 1.36.1 or higher.
Which versions of Forminator Forms are affected by CVE-2024-9700?
All versions of Forminator Forms up to and including 1.36.0 are affected by CVE-2024-9700.
What type of vulnerability is CVE-2024-9700?
CVE-2024-9700 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
What functionality is impacted by CVE-2024-9700?
CVE-2024-9700 impacts the submit_quizzes() function of the Forminator Forms plugin, allowing unauthorized access to user-controlled 'entry_id' parameters.