CVE Database /
CVE-2024-56276
CVE · Medium
CVE-2024-56276 — WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.2.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-56276
|
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.2.3 |
Missing Authorization |
Medium
4.3
|
< 1.9.2.3
|
1.9.2.3 |
2025-01-03 |
—
|
CVE-2024-56276
The WPForms plugin for WordPress up through version 1.9.2.2 contains a vulnerability where a function lacks proper capability verification. This flaw allows any authenticated user with Contributor-level permissions or higher to execute actions they should not have authorization to perform. The issue stems from missing access controls on the vulnerable function.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings