The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-03-07T08:16:22
Updated: 2024-08-02T23:18:41.802Z
Reserved: 2022-01-10T00:00:00
Link: CVE-2022-0163
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-03-07T09:15:08.937
Modified: 2022-03-11T20:27:47.033
Link: CVE-2022-0163
Redhat
No data.