PT-2026-57114 · WordPress · Flo Forms
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FlowForms – Conversational Form Builder versions prior to 1.1.2
Description
An Insecure Direct Object Reference (IDOR) exists in the
update form function due to missing validation on a user-controlled key. Authenticated attackers with contributor-level access or higher can modify the content, design, and settings of any form on the site, including those owned by administrators, or publish and revert them by providing an arbitrary form ID in the REST URL.Recommendations
Update FlowForms – Conversational Form Builder to version 1.1.2 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flo Forms