CVE-2024-1640

MEDIUM

Contact Form Builder Plugin <2.10.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. This makes it possible for unauthenticated attackers to modify form submissions.

Scores

CVSS v3 5.3
EPSS 0.0028
EPSS Percentile 51.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
bitapps/contact_form_builder < 2.10.2
bitpressadmin/Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder < 2.10.1
Published Mar 13, 2024
Tracked Since Feb 18, 2026