The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and including, 2.9.9.7. This makes it possible for unauthenticated attackers to view form submissions.
References
Configurations
History
21 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/all-contact-form-integration-for-elementor/trunk/includes/export_csv.php#L14 - Product | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3056456%40all-contact-form-integration-for-elementor%2Ftrunk&old=3021680%40all-contact-form-integration-for-elementor%2Ftrunk&sfp_email=&sfph_mail= - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/6a40ed3c-1f4b-4bf7-b6f4-fc1e145cc989?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:theinnovs:eleforms:*:*:*:*:*:wordpress:*:* | |
First Time |
Theinnovs
Theinnovs eleforms |
|
CWE | CWE-862 |
Information
Published : 2024-05-02 17:15
Updated : 2025-03-21 16:15
NVD link : CVE-2024-2043
Mitre link : CVE-2024-2043
CVE.ORG link : CVE-2024-2043
JSON object : View
Products Affected
theinnovs
- eleforms
CWE
CWE-862
Missing Authorization