Description
WordPress Plugin Form Maker by 10Web-Mobile-Friendly Drag & Drop Contact Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently steal session data and possibly access admin areas of your website. WordPress Plugin Form Maker by 10Web-Mobile-Friendly Drag & Drop Contact Form Builder version 1.7.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.15 or latest
References
Related Vulnerabilities
WordPress Plugin Instagram Feed Unspecified Vulnerability (1.10.2)
WordPress Plugin GD bbPress Attachments Cross-Site Scripting (2.5)
WordPress Plugin FL3R FeelBox Multiple Vulnerabilities (8.1)
WordPress Plugin Email Subscribers & Newsletters Multiple Vulnerabilities (2.9)
WordPress 4.6.x Arbitrary File Deletion Vulnerability (4.6 - 4.6.11)