The Country State City Dropdown CF7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tc_csca_patch_settings function in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with subscriber access and above, to add states or cities to the dropdown.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-05-02T16:51:44.028Z
Updated: 2024-08-01T20:12:07.603Z
Reserved: 2024-04-09T16:17:04.416Z
Link: CVE-2024-3520

Updated: 2024-08-01T20:12:07.603Z

Status : Awaiting Analysis
Published: 2024-05-02T17:15:26.420
Modified: 2024-11-21T09:29:46.280
Link: CVE-2024-3520

No data.