PT-2026-78353 · WordPress · Balbooa Forms
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Balbooa Forms versions prior to 2.4.3.2
Description
An unauthenticated attacker can perform PHP code injection due to the use of the
eval() function in the optional custom-PHP post-submission handler. The [URL parameter = X] shortcode is replaced with the raw, unescaped value of a query parameter, allowing arbitrary PHP code to execute on the server. Although a CSRF (Cross-Site Request Forgery) token is required to access the endpoint, it is disclosed anonymously through a separate task. This issue is exploitable if the form has a custom-PHP handler configured that references the shortcode and does not use reCAPTCHA on the submit button.Recommendations
Update to version 2.4.3.2 or later.
As a temporary mitigation, disable the custom-PHP post-submission handler or implement reCAPTCHA on the submit button.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Balbooa Forms