CVE-2024-12184

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 1, 2025
CWE ID 862

Summary

CVE-2024-12184 is a vulnerability affecting the Contact Forms plugin by Cimatti for WordPress. The issue lies in the lack of capability checks on the accua_forms_download_submitted_file() function. As a result, unauthenticated attackers can exploit this vulnerability to gain unauthorized access to other user-submitted form data, putting sensitive information at risk. Versions of the plugin up to and including 1.9.4 are affected. It is recommended that users update to the latest version of the plugin to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share