The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions up to, and including, 3.7.3.2. This makes it possible for unauthenticated attackers to delete arbitrary media files.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Oct 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:funnelforms:funnelforms_free:*:*:*:*:*:wordpress:*:* |
Thu, 29 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Funnelforms
Funnelforms funnelforms Free |
|
CPEs | cpe:2.3:a:funnelforms:funnelforms_free:-:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Funnelforms
Funnelforms funnelforms Free |
|
Metrics |
ssvc
|
Thu, 29 Aug 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions up to, and including, 3.7.3.2. This makes it possible for unauthenticated attackers to delete arbitrary media files. | |
Title | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Deletion | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-08-29T03:30:44.662Z
Updated: 2024-08-29T13:57:35.903Z
Reserved: 2024-06-11T13:05:01.436Z
Link: CVE-2024-5857
Vulnrichment
Updated: 2024-08-29T13:57:23.152Z
NVD
Status : Analyzed
Published: 2024-08-29T11:15:27.780
Modified: 2024-10-04T12:59:27.290
Link: CVE-2024-5857
Redhat
No data.