Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High2
Medium3
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2025-02-24

CVE-2024-12184 - Wordpress Contact Forms Plugin

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user submitted forms.

PLUGIN Wordpress Contact Forms

CVE-2024-12184

MEDIUM CVSS 5.3 2025-02-01
Threat Entry Updated 2025-03-19

CVE-2024-10521 - Wordpress Contact Forms Plugin

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wordpress Contact Forms

CVE-2024-10521

MEDIUM CVSS 4.3 2024-11-27
Scroll to top