The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:52:09.047Z

Updated: 2024-01-16T15:52:09.047Z

Reserved: 2022-01-12T09:37:44.754Z


Link: CVE-2022-23180

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-16T16:15:09.787

Modified: 2024-01-24T14:06:58.647


Link: CVE-2022-23180

JSON object: View

cve-icon Redhat Information

No data.

CWE