Vulnerabilities (CVE)

Filtered by vendor Wpmet Subscribe
Filtered by product Metform Elementor Contact Form Builder
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6788 1 Wpmet 1 Metform Elementor Contact Form Builder 2024-01-11 N/A 5.4 MEDIUM
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is due to missing or incorrect nonce validation on the contents function. This makes it possible for unauthenticated attackers to update the options "mf_hubsopt_token", "mf_hubsopt_refresh_token", "mf_hubsopt_token_type", and "mf_hubsopt_expires_in" via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This would allow an attacker to connect their own Hubspot account to a victim site's metform to obtain leads and contacts.
CVE-2022-1442 1 Wpmet 1 Metform Elementor Contact Form Builder 2022-05-18 5.0 MEDIUM 7.5 HIGH
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.