CVE Database /
CVE-2024-11205
CVE · Medium
CVE-2024-11205 — WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] >= 1.8.4 - < 1.9.2.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-11205
|
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] >= 1.8.4 - < 1.9.2.2 |
Missing Authorization |
Medium
6.5
|
1.8.4–1.9.2.2
|
1.9.2.2 |
2024-12-09 |
—
|
CVE-2024-11205
The WPForms plugin contains a capability verification gap in the 'wpforms_is_admin_page' function that permits authenticated users with minimal privileges (Subscriber level or higher) to perform unauthorized actions on the platform. Attackers exploiting this weakness between versions 1.8.4 and 1.9.2.1 can process refunds and terminate active subscriptions without proper authorization checks.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings