CVE-2024-0371
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 5, 2024
Updated: Feb 10, 2024
CWE ID 862
Summary
CVE-2024-0371 is a vulnerability affecting the Views for WPForms plugin for WordPress. This issue allows authenticated attackers with subscriber access or higher to bypass a capability check on the 'create_view' function, enabling them to unauthorized modify data and create form views. Versions up to and including 3.2.2 are vulnerable to this exploit. This vulnerability poses a significant risk for websites using the plugin and should be addressed promptly by applying the available patch or upgrading to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share