Input validation vulnerability in WordPress Contact Forms by Cimatti 1.6.0

The Contact Forms by Cimatti plugin for WordPress is vulnerable to a type of security issue called Cross-Site Request Forgery. This type of security issue exists in versions up to and including 1.6.0 of the plugin. The vulnerability is caused by the missing or incorrect validation of something called a “nonce” on the accua_forms_list_page_table function. This means that people without proper authorization, such as attackers, could possibly delete posts if they can convince a site administrator to click on a link.

Detected in:

Contact Forms by Cimatti fixed vulnerable versions:
WordPress Contact Forms by Cimatti open vulnerable versions: >= * <= 1.6.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.