Executive brief
The ThemeHunk Contact Form & Lead Form Elementor Builder plugin for WordPress, which helps users create custom contact and lead generation forms, contains a security flaw in its access control settings. An attacker could potentially trick a site administrator into performing unintended actions, such as modifying form settings or deleting data, by getting them to click a malicious link. This could lead to unauthorized changes to how the website collects lead information or disrupt the site's contact functionality.
Technical details
A missing authorization vulnerability (CWE-862) exists in the ThemeHunk Contact Form & Lead Form Elementor Builder plugin for WordPress through version 1.8.4. The vulnerability stems from incorrectly configured access control security levels and a lack of proper nonce validation, effectively making it susceptible to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can exploit this by inducing a privileged user (such as an administrator) to interact with a specially crafted link or page. Successful exploitation allows the attacker to execute administrative actions or modify plugin settings without proper authorization. The issue is resolved in version 1.8.5.
Affected products
- ThemeHunk Contact Form & Lead Form Elementor Builder <= 1.8.4
Timeline
- 2022-09-10: disclosed: Reported by István Márton
- 2023-06-27: advisory: Initial advisory published by Patchstack
- 2026-06-11: patched: NVD publication date (Note: Patch version 1.8.5 was available earlier)