CVE-2024-6628

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.9.9. This is due to missing or incorrect nonce validation when deleting form submissions. This makes it possible for unauthenticated attackers to delete form submissions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Configurations

Configuration 1 (hide)

cpe:2.3:a:theinnovs:eleforms:*:*:*:*:*:wordpress:*:*

History

31 Mar 2025, 19:58

Type Values Removed Values Added
References () https://wordpress.org/plugins/all-contact-form-integration-for-elementor/#developers - () https://wordpress.org/plugins/all-contact-form-integration-for-elementor/#developers - Release Notes
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/c21f5461-9c1e-48ec-b15f-6a9be1e27b43?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/c21f5461-9c1e-48ec-b15f-6a9be1e27b43?source=cve - Third Party Advisory
CPE cpe:2.3:a:theinnovs:eleforms:*:*:*:*:*:wordpress:*:*
First Time Theinnovs
Theinnovs eleforms

Information

Published : 2024-11-16 04:15

Updated : 2025-03-31 19:58


NVD link : CVE-2024-6628

Mitre link : CVE-2024-6628

CVE.ORG link : CVE-2024-6628


JSON object : View

Products Affected

theinnovs

  • eleforms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)