Description
WordPress Plugin Form Maker by 10Web-Mobile-Friendly Drag & Drop Contact Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently steal session data and possibly access admin areas of your website. WordPress Plugin Form Maker by 10Web-Mobile-Friendly Drag & Drop Contact Form Builder version 1.7.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.15 or latest
References
Related Vulnerabilities
WordPress Plugin WP-CopyProtect [Protect your blog posts] Cross-Site Scripting (3.0.0)
PmWiki Other Vulnerability (CVE-2006-4453)
MySQL CVE-2014-0427 Vulnerability (CVE-2014-0427)
WordPress Plugin Bulk Delete Privilege Escalation (5.5.3)
WordPress Plugin WP Support Plus Responsive Ticket System SQL Injection (7.1.4)