The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability check on the duplicateForm function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with subscriber access or higher, to duplicate arbitrary posts and pages.
History

Wed, 05 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Wobbie
Wobbie mollie Forms
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:wobbie:mollie_forms:*:*:*:*:*:wordpress:*:*
Vendors & Products Wobbie
Wobbie mollie Forms

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-05T17:44:22.686Z

Reserved: 2024-02-09T14:30:01.475Z

Link: CVE-2024-1400

cve-icon Vulnrichment

Updated: 2024-08-01T18:40:20.843Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-11T22:15:54.490

Modified: 2025-02-05T20:56:20.887

Link: CVE-2024-1400

cve-icon Redhat

No data.