CVE-2023-0689CVSS 4.3Web
CVE-2023-0689: metform elementor contact form builder vulnerability
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, including the submitter's first name.
- CVSS
- 4.3 MEDIUM
- EPSS
- 37.39%
- Known exploited
- not in KEV
- Product
- metform elementor contact form builder
What is known
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, including the submitter's first name.