HIGH🇵🇱 Wersja polska

CVE-2024-11205

CVSS 8.5v3.1pub. 2024-12-10upd. 2025-08-12

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
  • Wpforms

    APP
    Wpforms
    1.8.4 – 1.9.2.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-7063HIGH7.2same product

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission paramete...

CVE-2020-36919MEDIUM5.1same product

WPForms 1.7.8 zawiera lukę typu cross-site scripting w funkcji importu suwaka oraz parametrze tab. Atakujący m...

CVE-2024-13403MEDIUM6.4same product

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordP...

CVE-2024-56276MEDIUM4.3same product

Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Inco...

CVE-2024-11223MEDIUM4.7same product

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could al...