cleantalk
Vulnerabilities and Security Researches

Forminator – Contact Form, Payment Form & Custom Form Builder, ced7f8be-acd4-4d6f-9745-6a1e57d4e5a9

Published on
-
Research Description
Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder [forminator] < 1.14.8.1 Multiple Plugins - CSRF Nonce Bypasses Multiple plugins did not properly check for CRSF nonces, allowing attackers to make logged in users do unwanted actions with crafted requests not containing the related nonce parameter. Other plugins reported in the original advisory which are not here have been added individually in the last weeks
Affected versions
max 1.14.8.1.
Status
vulnerable