Files
CVEs-PoC/2023/CVE-2023-0692.md
T
2025-09-29 21:09:30 +02:00

1009 B

CVE-2023-0692

Description

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the payment status of arbitrary form submissions.

POC

Reference

No PoCs from references.

Github