The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
History

Mon, 16 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:52:09.047Z

Updated: 2025-06-16T18:03:39.592Z

Reserved: 2022-01-12T09:37:44.754Z

Link: CVE-2022-23180

cve-icon Vulnrichment

Updated: 2024-08-03T03:36:19.950Z

cve-icon NVD

Status : Modified

Published: 2024-01-16T16:15:09.787

Modified: 2025-06-16T18:15:19.997

Link: CVE-2022-23180

cve-icon Redhat

No data.