CVE Database
/

CVE-2022-0404

Back to search

CVE-2022-0404

Published: Apr 4, 2022

Modified: Aug 2, 2024

PUBLISHED

Description

The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.

VendorProductVersions

Unknown

Material Design for Contact Form 7

affected
0 - <= 2.6.4

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now