CVE Published: 07/03/2022 |
CVE Updated: 02/08/2024 |
CVE Year: 2022 Source: WPScan |
Vendor: Unknown |
Product: Smart Forms – when you need more than just a contact form Status : PUBLISHED
CVE-2022-0163 Description
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form\'s data, which could include sensitive information such as PII depending on the form.