CVE-2024-1416

MEDIUM

Responsive Contact Form Builder & Lead Generation Plugin <2.0 - Pri...

Title source: llm
STIX 2.1

Description

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions.

Scores

CVSS v3 4.3
EPSS 0.0027
EPSS Percentile 19.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (2)
themehunk/Lead Form Builder & Contact Form < 1.8.9
themehunk/Responsive Contact Form Builder & Lead Generation Plugin < 1.8.9
Published May 02, 2024
Tracked Since Feb 18, 2026