vcita Contact Form and Calls To Action
cpe:2.3:a:vcita:contact_form_and_calls_to_action_by_vcita:*:*:*:*:wordpress:*:*
- <= 2.7.1
A vulnerability exists in the Contact Form and Calls To Action by vcita plugin for WordPress, in all versions through 2.7.1. The issue arises from a lack of proper capability checks in the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions. This flaw allows authenticated attackers with subscriber-level access and above to unauthorizedly modify widget settings, enabling or disabling widgets at will.
Exploitation of this vulnerability allows for unauthorized modification of widget settings, specifically enabling or disabling widgets on the site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.