CVE-2024-12184
01.02.2025, 04:15
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user submitted forms.Enginsight
Vendor | Product | Version |
---|---|---|
cimatti | wordpress_contact_forms | 𝑥 < 1.9.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References