WS Form LITE – Drag & Drop Contact Form Builder for WordPress, CVE-2025-3912
- CVE, Research URL
- Home page URL
-
Security reports for WS Form LITE – Drag & Drop Contact Form Builder for WordPress
- Published on
- Apr 25, 2025
- Research Description
- The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services.
- Affected versions
-
Min -, max 1.10.36.
- Status
-
vulnerable
Previous vulnerability researches |
---|
WooCommerce PayPal Checkout Payment Gateway (CVE-2019-7441) , Jun 07, 2024 |
WooCommerce PayPal Checkout Payment Gateway (CVE-2019-14979) , Jun 07, 2024 |