WPIntell

Source evidence

Cross-Site Request Forgery Vulnerability

Contact Form by Supsystic · support · 2024-01-29T18:39:00+00:00

complaintsentiment
highseverity
1.0relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 36 rows with source links

19.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
geekwap unresolved
Hello, Wordfence found this vulnerability: The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.27. This is due to missing nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. When will there be a new release that fixes this vulnerability? Thanks Much! Matt We are getting notice of the Cross Site Request Forgery (CSRF) vulnerability as well. Please update this as soon as possible. Any ETA on fixing this? Its been an issue for months https://www.cve.org/CVERecord?id=CVE-2023-45068 This reply was modified 2 years, 1 month ago by gruntlord6 .

Comments

2 shown
Ed N. 2024-03-26T16:10:00+00:00

We are getting notice of the Cross Site Request Forgery (CSRF) vulnerability as well. Please update this as soon as possible.

gruntlord6 2024-05-09T17:10:00+00:00

Any ETA on fixing this? Its been an issue for months https://www.cve.org/CVERecord?id=CVE-2023-45068 This reply was modified 2 years, 1 month ago by gruntlord6 .