CVE-2024-13717
EUVD-2024-5173231.01.2025, 06:15
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to enabled and disable widgets.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| vcita | contact_form_and_calls_to_action_by_vcita | 𝑥 ≤ 2.7.1 | CNA |
Common Weakness Enumeration