Forminator – Contact Form, Payment Form & Custom Form Builder, a282153c8d6d6d62beb2b381a06ecc2da5ecfb06
- CVE, Research URL
- Home page URL
-
Security reports for Forminator – Contact Form, Payment Form & Custom Form Builder
- Published on
- Apr 12, 2023
- Research Description
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.23.3 Forminator <= 1.22.1 - Missing Authorization on 'hubspot_support_request' AJAX function The Forminator plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'hubspot_support_request' AJAX function in versions up to, and including, 1.22.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to submit support requests via the Hubspot API.
- Affected versions
-
max 1.23.3.
- Status
-
vulnerable