The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. This makes it possible for unauthenticated attackers to modify form submissions.
CVSS
No CVSS.
References
Configurations
History
03 Apr 2025, 13:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/49ed7d6a-4a65-4efc-90e5-ffa5470d4011?source=cve - Third Party Advisory | |
References | () https://plugins.trac.wordpress.org/changeset/3048523/bit-form/trunk/includes/Frontend/Ajax/FrontendAjax.php - Patch | |
First Time |
Bitapps contact Form Builder
Bitapps |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:bitapps:contact_form_builder:*:*:*:*:*:wordpress:*:* |
13 Mar 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-13 16:15
Updated : 2025-04-03 13:12
NVD link : CVE-2024-1640
Mitre link : CVE-2024-1640
JSON object : View
Products Affected
bitapps
- contact_form_builder
CWE