Description
WordPress Plugin Smart Forms-when you need more than just a contact form is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update arbitrary options (such as default_role and users_can_register). WordPress Plugin Smart Forms-when you need more than just a contact form version 2.6.84 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.6.85 or latest
References
Related Vulnerabilities
phpBB Improper Input Validation Vulnerability (CVE-2006-2220)
WordPress Plugin FlyingPress Security Bypass (3.9.6)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-40177)
MySQL CVE-2023-22058 Vulnerability (CVE-2023-22058)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5317)