cleantalk
Vulnerabilities and Security Researches

Metform Elementor Contact Form Builder, CVE-2023-0694

CVE, Research URL

CVE-2023-0694

Published on
Jun 09, 2023
Research Description
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about any standard form field of any form submission.
Affected versions
Min -, max 3.3.2.
Status
vulnerable