Access violation vulnerability in Quform – WordPress Form Builder 2.20.0

The Quform plugin for WordPress allows users to create forms on their website. However, it has a vulnerability that can expose sensitive information, like personal data, from uploaded files. This means that hackers can access this information without needing to log in. Even if the plugin is updated, forms created before a certain version will still be vulnerable. To fully protect against this, site administrators should download any previously uploaded files, delete existing files and forms, and create new forms after updating to the latest version.

Detected in:

Quform - WordPress Form Builder fixed vulnerable versions: >= * <= 2.20.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.