PT-2026-67010 · WordPress · Gutena Forms
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder versions prior to 1.9.1
Description
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can modify the read/unread status of or permanently trash arbitrary form submission entries for any form. This occurs because the nonce (a unique token used to prevent cross-site request forgery) issued by the
check ajax referer() function is emitted to unauthenticated visitors via wp localize script() on any public page containing a Gutena Forms block, allowing anonymous attackers to obtain it easily.Recommendations
Update Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder to version 1.9.1 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gutena Forms