The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and including, 2.9.9.7. This makes it possible for unauthenticated attackers to view form submissions.
References
Configurations
History
21 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Theinnovs eleforms
Theinnovs |
|
CWE | CWE-862 | |
CPE | cpe:2.3:a:theinnovs:eleforms:*:*:*:*:*:wordpress:*:* | |
References | () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/export_csv.php#L14 - Product | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3056456%40all-contact-form-integration-for-elementor%2Ftrunk&old=3021680%40all-contact-form-integration-for-elementor%2Ftrunk&sfp_email=&sfph_mail= - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/6a40ed3c-1f4b-4bf7-b6f4-fc1e145cc989?source=cve - Third Party Advisory |
21 Nov 2024, 09:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/export_csv.php#L14 - | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3056456%40all-contact-form-integration-for-elementor%2Ftrunk&old=3021680%40all-contact-form-integration-for-elementor%2Ftrunk&sfp_email=&sfph_mail= - | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/6a40ed3c-1f4b-4bf7-b6f4-fc1e145cc989?source=cve - | |
Summary |
|
02 May 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-02 17:15
Updated : 2025-03-21 16:15
NVD link : CVE-2024-2043
Mitre link : CVE-2024-2043
CVE.ORG link : CVE-2024-2043
JSON object : View
Products Affected
theinnovs
- eleforms
CWE
CWE-862
Missing Authorization