Show filters
157 Total Results
Displaying 111-120 of 157
Sort by:
Attacker Value
Unknown
CVE-2023-0694
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about any standard form field of any form submission.
0
Attacker Value
Unknown
CVE-2023-0693
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction_id' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the transaction ids of arbitrary form submissions that included payment.
0
Attacker Value
Unknown
CVE-2023-0692
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the payment status of arbitrary form submissions.
0
Attacker Value
Unknown
CVE-2023-0691
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, specifically the submitter's last name.
0
Attacker Value
Unknown
CVE-2023-0688
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about form submissions, including payment status, and transaction ID.
0
Attacker Value
Unknown
CVE-2023-2301
Disclosure Date: June 03, 2023 (last updated October 08, 2023)
The Contact Form Builder by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.1. This is due to missing nonce validation on the ls_parse_vcita_callback function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-2300
Disclosure Date: June 03, 2023 (last updated October 08, 2023)
The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 4.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as contributors and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-45838
Disclosure Date: April 18, 2023 (last updated October 08, 2023)
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions.
0
Attacker Value
Unknown
CVE-2023-0816
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
0
Attacker Value
Unknown
CVE-2023-0484
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
0