CVE-2024-0660

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_settings function. This makes it possible for unauthenticated attackers to change form settings and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Configurations

Configuration 1 (hide)

cpe:2.3:a:strategy11:formidable_forms:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 6.1
References () https://plugins.trac.wordpress.org/changeset/3026901/formidable/tags/6.8/classes/controllers/FrmFormsController.php - Patch () https://plugins.trac.wordpress.org/changeset/3026901/formidable/tags/6.8/classes/controllers/FrmFormsController.php - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/b983d22b-6cd2-4450-99e2-88bb149091fe?source=cve - Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/b983d22b-6cd2-4450-99e2-88bb149091fe?source=cve - Third Party Advisory

13 Feb 2024, 14:05

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/changeset/3026901/formidable/tags/6.8/classes/controllers/FrmFormsController.php - () https://plugins.trac.wordpress.org/changeset/3026901/formidable/tags/6.8/classes/controllers/FrmFormsController.php - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/b983d22b-6cd2-4450-99e2-88bb149091fe?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/b983d22b-6cd2-4450-99e2-88bb149091fe?source=cve - Third Party Advisory
Summary
  • (es) El complemento Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder para WordPress es vulnerable a Cross-Site Request Forgery en todas las versiones hasta la 6.7.2 incluida. Esto se debe a una validación nonce faltante o incorrecta en la función update_settings. Esto hace posible que atacantes no autenticados cambien la configuración del formulario y agreguen JavaScript malicioso a través de una solicitud falsificada, siempre que puedan engañar al administrador del sitio para que realice una acción como hacer clic en un enlace.
First Time Strategy11
Strategy11 formidable Forms
CWE CWE-352
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:strategy11:formidable_forms:*:*:*:*:*:wordpress:*:*

05 Feb 2024, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-05 22:16

Updated : 2024-11-21 08:47


NVD link : CVE-2024-0660

Mitre link : CVE-2024-0660

CVE.ORG link : CVE-2024-0660


JSON object : View

Products Affected

strategy11

  • formidable_forms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)