First published: Fri Jan 24 2025(Updated: )
Missing Authorization vulnerability in Vikas Ratudi VForm allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects VForm: from n/a through 3.0.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vikas Ratudi VForm | <=3.0.5 | |
WordPress VForm | <=3.0.5 |
Update the WordPress VForm wordpress plugin to the latest available version (at least 3.0.7).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24604 is classified as a missing authorization vulnerability.
To fix CVE-2025-24604, ensure that access control security levels are properly configured in Vikas Ratudi VForm.
CVE-2025-24604 affects Vikas Ratudi VForm versions up to and including 3.0.5.
Yes, CVE-2025-24604 allows exploiting incorrectly configured access control security levels, potentially leading to unauthorized access.
The same mitigation steps for Vikas Ratudi VForm apply to WordPress VForm versions up to 3.0.5 concerning CVE-2025-24604.