The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action
History

Wed, 30 Apr 2025 06:15:00 +0000

Type Values Removed Values Added
Description The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action
Title SureForms < 1.4.4 - Contributor+ Settings Update
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-04-30T06:00:04.092Z

Updated: 2025-04-30T06:00:04.092Z

Reserved: 2025-04-09T14:55:58.875Z

Link: CVE-2025-3471

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-04-30T06:15:53.153

Modified: 2025-04-30T06:15:53.153

Link: CVE-2025-3471

cve-icon Redhat

No data.