CVE Database /
CVE-2023-0693
CVE · Medium
CVE-2023-0693 — MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.3.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-0693
|
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.3.2 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 3.3.2
|
3.3.2 |
2023-06-08 |
—
|
CVE-2023-0693
The Metform plugin for Elementor versions up to 3.3.1 contains an information disclosure vulnerability in the 'mf_transaction_id' shortcode that allows authenticated users with subscriber-level access or higher to retrieve sensitive transaction IDs associated with payment-enabled form submissions. Attackers can exploit this flaw to access confidential payment transaction information they should not have permission to view. The vulnerability was patched in version 3.3.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings