CVE-2024-6628
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-6628 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the EleForms – All In One Form Integration plugin for WordPress. Versions up to and including 2.9.9.9 are impacted by this issue. The flaw arises due to insufficient nonce validation when deleting form submissions, which enables unauthenticated attackers to manipulate administrators into deleting submissions through maliciously crafted links. This vulnerability could potentially lead to data loss and unwanted modifications to form submissions. It is crucial for WordPress users to update their plugins to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.