SureForms < 1.4.4 - Contributor+ Settings Update
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.9epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · SureForms