WS Form LITE – Drag & Drop Contact Form Builder for WordPress, CVE-2025-3912
- CVE, Research URL
- Home page URL
-
Security reports for WS Form LITE – Drag & Drop Contact Form Builder for WordPress
- Published on
- Apr 25, 2025
- Research Description
- The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services.
- Affected versions
-
Min -, max 1.10.36.
- Status
-
vulnerable
Previous vulnerability researches |
---|
BeerXML Shortcode (CVE-2025-46511) , Apr 26, 2025 |