Conversation
supportHello, Wordfence found this vulnerability: The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.27. This is due to missing nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. When will there be a new release that fixes this vulnerability? Thanks Much! Matt
We are getting notice of the Cross Site Request Forgery (CSRF) vulnerability as well. Please update this as soon as possible.
Any ETA on fixing this? Its been an issue for months https://www.cve.org/CVERecord?id=CVE-2023-45068 This reply was modified 2 years, 1 month ago by gruntlord6 .
We are getting notice of the Cross Site Request Forgery (CSRF) vulnerability as well. Please update this as soon as possible.
Any ETA on fixing this? Its been an issue for months https://www.cve.org/CVERecord?id=CVE-2023-45068 This reply was modified 2 years, 1 month ago by gruntlord6 .