Description
WordPress Plugin Form Maker by 10Web-Mobile-Friendly Drag & Drop Contact Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently steal session data and possibly access admin areas of your website. WordPress Plugin Form Maker by 10Web-Mobile-Friendly Drag & Drop Contact Form Builder version 1.7.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.15 or latest
References
Related Vulnerabilities
Nginx Off-by-one Error Vulnerability (CVE-2021-23017)
Ampache Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-4665)
Microsoft SQL Server CVE-2023-32028 Vulnerability (CVE-2023-32028)
Joomla CVE-2022-23799 Vulnerability (CVE-2022-23799)
WordPress Plugin NextCellent Gallery-NextGEN Legacy Cross-Site Scripting (1.9.27)