CVE-2025-30809: WordPress WordPress Contact Form, Drag and Drop Form Builder Plugin – Live Forms plugin <= 4.8.4 - Settings Change vulnerability
Missing Authorization vulnerability in Shahjada Live Forms liveforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Forms: from n/a through <= 4.8.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30809?
CVE-2025-30809 has a high severity rating due to the potential for unauthorized access resulting from missing authorization in Shahjada Live Forms.
How do I fix CVE-2025-30809?
To fix CVE-2025-30809, update Shahjada Live Forms and the WordPress Contact Form plugin to the latest version available beyond 4.8.4.
Who is affected by CVE-2025-30809?
CVE-2025-30809 affects users of Shahjada Live Forms and the WordPress Contact Form, Drag and Drop Form Builder Plugin up to version 4.8.4.
What specific vulnerability is outlined in CVE-2025-30809?
CVE-2025-30809 outlines a missing authorization vulnerability that allows exploitation due to incorrectly configured access control security levels.
What can happen if CVE-2025-30809 is exploited?
If exploited, CVE-2025-30809 can lead to unauthorized actions being performed by users who should not have access, compromising data integrity and security.