The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-16T15:52:09.047Z
Updated: 2024-08-03T03:36:19.950Z
Reserved: 2022-01-12T09:37:44.754Z
Link: CVE-2022-23180
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-01-16T16:15:09.787
Modified: 2024-11-21T06:48:08.517
Link: CVE-2022-23180
Redhat
No data.