The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:52:09.047Z

Updated: 2024-08-03T03:36:19.950Z

Reserved: 2022-01-12T09:37:44.754Z

Link: CVE-2022-23180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-16T16:15:09.787

Modified: 2024-01-24T14:06:58.647

Link: CVE-2022-23180

cve-icon Redhat

No data.