CVE-2024-1400
Last modified
CVE-2024-1400 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability check on the duplicateForm function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with subscriber access or higher, to duplicate arbitrary posts and pages.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability check on the duplicateForm function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with subscriber access or higher, to duplicate arbitrary posts and pages.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wobbie | Mollie Forms | < 2.6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-1400?
How severe is CVE-2024-1400?
How do I fix CVE-2024-1400?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13994Nagios XI versions prior to 2024R1.1.2 contain a missing aut…9.8
- CVE-2024-13995Nagios XI versions prior to 2024R1.1.2 may (confirmed in 202…8.8
- CVE-2024-13996Nagios XI versions prior to 2024R1.1.3 did not invalidate al…9.8
- CVE-2024-13997Nagios XI versions prior to 2024R1.1.3 contain a privilege e…7.2
- CVE-2024-13998Nagios XI versions prior to 2024R1.1.3, under certain circum…6.5
- CVE-2024-13999Nagios XI versions prior to 2024R1.1.3, under certain circum…9.8
- CVE-2024-14000Nagios XI versions prior to 2024R1.1.3 are vulnerable to cro…5.4
- CVE-2024-14001Nagios XI versions prior to 2024R1.1.3 are vulnerable to cro…5.4
- CVE-2024-14002Nagios XI versions prior to 2024R1.1.4 contain a local file …5.5
- CVE-2024-14003Nagios XI versions prior to 2024R1.2 are vulnerable to remot…9.8
- CVE-2024-14004Nagios XI versions prior to 2024R1.2 contain a privilege esc…8.8
- CVE-2024-14005Nagios XI versions prior to 2024R1.2 contain a command injec…8.8
Are you affected by CVE-2024-1400?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
