Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-4266

Опубликовано: 11 июн. 2024
Источник: nvd
CVSS3: 5.3
CVSS3: 7.5
EPSS Низкий

Описание

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wpmet:metform_elementor_contact_form_builder:*:*:*:*:*:wordpress:*:*
Версия до 3.8.9 (исключая)

EPSS

Процентиль: 80%
0.01362
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
github
больше 1 года назад

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users.

EPSS

Процентиль: 80%
0.01362
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

NVD-CWE-noinfo