Description
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter bookmark statuses.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17503 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter bookmark statuses. |
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Admin side data storage for Contact Form 7 <= 1.1.1 - Missing Authorization to Unauthenticated Bookmark Status Alteration |
Thu, 26 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zestard
Zestard admin Side Data Storage For Contact Form 7 |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:zestard:admin_side_data_storage_for_contact_form_7:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Zestard
Zestard admin Side Data Storage For Contact Form 7 |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:26:33.798Z
Reserved: 2024-02-22T18:38:00.751Z
Link: CVE-2024-1778
Updated: 2024-08-01T18:48:22.024Z
Status : Modified
Published: 2024-02-23T07:15:48.793
Modified: 2026-04-08T19:20:51.517
Link: CVE-2024-1778
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD