CVE-2023-1843 Information
Jun 10, 2023
cve
Description
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability check on the permalink_setup function in versions up to and including 3.3.0. This makes it possible for unauthenticated attackers to change the permalink structure.
Reference
https://plugins.trac.wordpress.org/changeset/2907471/ https://plugins.trac.wordpress.org/browser/metform/trunk/plugin.php#L544 https://www.wordfence.com/threat-intel/vulnerabilities/id/5db00eb6-3e05-42fa-bb84-2df4bcae3955?source=cve
Share on: