cve/2024/CVE-2024-5857.md
2024-08-30 20:52:42 +00:00

1008 B
Raw Blame History

CVE-2024-5857

Description

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions up to, and including, 3.7.3.2. This makes it possible for unauthenticated attackers to delete arbitrary media files.

POC

Reference

No PoCs from references.

Github