Quantcast
Channel: Topic Tag: forms | WordPress.org
Viewing all articles
Browse latest Browse all 3053

niravz on "[Plugin: WP-CRM - Customer Relations Management for WordPress] Possible Security Flaw in Shortcode Forms"

$
0
0

Hi Team,

I would like to know if there's some misconfiguration at my end or is it an actual security flaw - but would it be right to write the entire test case here in a public post?

The flaw that I found was when someone filled in the the Shortcode Form generated by WP-CRM (may be using CF7, I don't know) allows for updation of data of other users (e.g. First Name, Last Name, Phone Number) without valid authorization.

https://wordpress.org/plugins/wp-crm/


Viewing all articles
Browse latest Browse all 3053

Trending Articles