The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perform unauthorized actions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Apr 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rednao
Rednao smart Forms |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:rednao:smart_forms:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Rednao
Rednao smart Forms |
Fri, 09 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-09T19:06:05.756Z
Reserved: 2024-02-07T13:24:10.890Z
Link: CVE-2024-1307
Updated: 2024-08-01T18:33:25.411Z
Status : Analyzed
Published: 2024-04-15T05:15:14.813
Modified: 2025-04-08T19:43:21.050
Link: CVE-2024-1307
No data.
OpenCVE Enrichment
No data.
Weaknesses