The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 25 Apr 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services. | |
Title | WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to Unauthenticated Sensitive Information Exposure | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-04-25T11:12:52.021Z
Updated: 2025-04-25T13:53:42.292Z
Reserved: 2025-04-23T22:10:17.114Z
Link: CVE-2025-3912

Updated: 2025-04-25T13:53:38.506Z

Status : Awaiting Analysis
Published: 2025-04-25T12:15:17.243
Modified: 2025-04-29T13:52:28.490
Link: CVE-2025-3912

No data.