Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-1129


The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the set_starred() function in all versions up to, and including, 8.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark records as starred.


Published

2024-02-29T01:43:40.957

Last Modified

2025-01-15T17:27:54.877

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application basixonline nex-forms < 8.5.7 Yes

References