The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 16 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-16T15:52:09.047Z
Updated: 2025-06-16T18:03:39.592Z
Reserved: 2022-01-12T09:37:44.754Z
Link: CVE-2022-23180
Updated: 2024-08-03T03:36:19.950Z
Status : Modified
Published: 2024-01-16T16:15:09.787
Modified: 2025-06-16T18:15:19.997
Link: CVE-2022-23180
No data.