CVE-2024-0371

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 5, 2024
Updated: Feb 10, 2024
CWE ID 862

Summary

CVE-2024-0371 is a vulnerability affecting the Views for WPForms plugin for WordPress. This issue allows authenticated attackers with subscriber access or higher to bypass a capability check on the 'create_view' function, enabling them to unauthorized modify data and create form views. Versions up to and including 3.2.2 are vulnerable to this exploit. This vulnerability poses a significant risk for websites using the plugin and should be addressed promptly by applying the available patch or upgrading to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share