Wpmet
Wpmet Metform Elementor Contact Form Builder: vulnerabilidades y CVE
Wpmet Metform Elementor Contact Form Builder tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-50903 | Crítica (9.8) | 0.62% | — | 9 dic 2024 | Missing Authorization vulnerability in Roxnor Metform metform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform: from n/a through <= 3.4.0. |
| CVE-2023-0714 | Crítica (9.8) | 0.96% | — | 17 ago 2024 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.2.4. This allows unauthenticated visitors to… |
| CVE-2024-4266 | Alta (7.5) | 0.55% | — | 11 jun 2024 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function.… |
| CVE-2024-33570 | Alta (8.8) | 0.44% | — | 6 may 2024 | Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3. |
| CVE-2024-2791 | Media (5.4) | 0.32% | — | 2 abr 2024 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.8.5 due to insufficient input sanitization… |
| CVE-2024-1585 | Media (5.4) | 0.50% | — | 13 mar 2024 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.8.3 due to insufficient input… |
| CVE-2023-6788 | Media (5.4) | 0.23% | — | 9 ene 2024 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is due to missing or incorrect nonce validation on the… |
| CVE-2023-0689 | Media (4.3) | 0.58% | — | 31 ago 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with… |
| CVE-2023-2517 | Media (4.3) | 0.40% | — | 12 jul 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on the… |
| CVE-2023-1843 | Media (5.3) | 0.63% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability check on the permalink_setup function in versions up to, and… |
| CVE-2023-0721 | Alta (7.8) | 0.71% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV… |
| CVE-2023-0710 | Media (5.4) | 0.39% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attribute of the 'mf_thankyou' shortcode to echo unescaped form submissions in versions up to, and… |
| CVE-2023-0709 | Media (5.4) | 0.55% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This… |
| CVE-2023-0708 | Media (5.4) | 0.57% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This… |
| CVE-2023-0695 | Media (5.4) | 0.41% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows… |
| CVE-2023-0694 | Media (4.3) | 0.66% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level… |
| CVE-2023-0693 | Media (4.3) | 0.66% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction_id' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with… |
| CVE-2023-0692 | Media (4.3) | 0.60% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with… |
| CVE-2023-0691 | Media (4.3) | 0.60% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with… |
| CVE-2023-0688 | Media (6.5) | 0.73% | — | 9 jun 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with… |
| CVE-2023-0084 | Media (6.1) | 29% | — | 2 mar 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and… |
| CVE-2023-0085 | Media (5.3) | 0.69% | — | 2 mar 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted… |
| CVE-2022-1442 | Alta (7.5) | 8.8% | — | 10 may 2022 | The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Wpmet
WP Ultimate Review · 16Elements KIT Elementor Addons · 14Elementskit · 11Elementskit Elementor Addons · 10Fundengine · 8Gutenkit · 7WP Social Login AND Register Social Counter · 6Elementskit Lite · 2Elementskit Elementor Addons Lite · 2WP Fundraising Donation AND Crowdfunding Platform · 1Metform · 1Shopengine · 1