PT-2026-102708 · WordPress · Balbooa Forms
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Balbooa Forms versions prior to 2.4.3.4
Description
An unauthenticated remote code execution (RCE) issue exists in the
com baforms component. The software allows administrators to define PHP code that executes after a public form submission, which supports the use of form-field shortcodes. The component fails to properly sanitize these shortcodes before passing them to the eval() function, replacing them with raw values submitted by the visitor. This allows an attacker to execute arbitrary code if a public form utilizes the optional PHP-after-submission action and interpolates an attacker-controlled field shortcode within a double-quoted PHP string.Recommendations
Update to version 2.4.3.4 or later.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Balbooa Forms