CVE-2024-1779
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 23, 2024
Summary
CVE-2024-1779 is a vulnerability affecting the Contact Form 7 plugin for WordPress. The issue lies in the zt_dcfcf_change_status() function, which lacks proper capability checks. This oversight results in unauthenticated attackers being able to modify the read status of messages in the Admin side data storage. The consequences of this vulnerability could lead to misinformation or unintended actions based on the altered message status. WordPress users running versions up to and including 1.1.1 are at risk and are advised to update as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share