Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1217

Опубликовано: 29 фев. 2024
Источник: nvd
CVSS3: 7.6
CVSS3: 4.3
EPSS Низкий

Описание

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kaliforms:contact_form_builder:*:*:*:*:*:wordpress:*:*
Версия до 2.3.42 (исключая)

EPSS

Процентиль: 20%
0.00064
Низкий

7.6 High

CVSS3

4.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.6
github
почти 2 года назад

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.

EPSS

Процентиль: 20%
0.00064
Низкий

7.6 High

CVSS3

4.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo