Junglewise Threat Intelligence

CVE-2023-25969: ThemeHunk Contact Form & Lead Form Elementor Builder missing authorization

CVE-2023-25969 · Severity: medium · CVSS 5.4 · Published 2026-06-11

Vendors: ThemeHunk.

Executive brief

The ThemeHunk Contact Form & Lead Form Elementor Builder plugin for WordPress, which helps users create custom contact and lead generation forms, contains a security flaw in its access control settings. An attacker could potentially trick a site administrator into performing unintended actions, such as modifying form settings or deleting data, by getting them to click a malicious link. This could lead to unauthorized changes to how the website collects lead information or disrupt the site's contact functionality.

Technical details

A missing authorization vulnerability (CWE-862) exists in the ThemeHunk Contact Form & Lead Form Elementor Builder plugin for WordPress through version 1.8.4. The vulnerability stems from incorrectly configured access control security levels and a lack of proper nonce validation, effectively making it susceptible to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can exploit this by inducing a privileged user (such as an administrator) to interact with a specially crafted link or page. Successful exploitation allows the attacker to execute administrative actions or modify plugin settings without proper authorization. The issue is resolved in version 1.8.5.

Affected products

  • ThemeHunk Contact Form & Lead Form Elementor Builder <= 1.8.4

Timeline

  • 2022-09-10: disclosed: Reported by István Márton
  • 2023-06-27: advisory: Initial advisory published by Patchstack
  • 2026-06-11: patched: NVD publication date (Note: Patch version 1.8.5 was available earlier)

References