PT-2026-33019 · Forfront+1 · E-Shot+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
e-shot™ form builder plugin for WordPress versions prior to 1.0.3
Description
The plugin contains a missing authorization flaw in the
eshot form builder update field data() AJAX handler. The function is registered via the wp ajax hook but fails to implement capability checks using current user can() or nonce verification through check ajax referer() or wp verify nonce(). Consequently, authenticated users with Subscriber-level access or higher can modify form field configurations, such as mandatory status, field visibility, and form display preferences, by interacting with the eshot form builder update field data AJAX action.Recommendations
Update the e-shot™ form builder plugin for WordPress to version 1.0.3 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E-Shot
E-Shot Form Builder