CVE-2024-56276

WordPress WPForms Lite plugin <= 1.9.2.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.


We have discovered 268,820 live websites that are affected by CVE-2024-56276.

Run a Free Instant Scan




Affected Software

Product  WPForms
Category Form Builders
Vulnerable Domains268,820 live websites (48.78% of WPForms install base)
Vulnerable Versions
  • from 0 through 1.9.2.2
Vulnerable Versions Count189 versions ( 94.50% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 7, 2025
  • Updated - Jan 7, 2025

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2024-56276 usage by Country

United States90,612 websites



Germany34,336 websites
France17,107 websites
GB11,459 websites
Cyprus11,069 websites
Italy8,847 websites
Netherlands6,716 websites
Spain5,731 websites
Poland5,472 websites
Russia4,751 websites

CVE-2024-56276 usage by TLD

.com117,095 websites
.de13,182 websites
.org12,279 websites
.co.uk8,275 websites
.nl7,172 websites
.it6,823 websites
.fr6,731 websites
.com.br6,125 websites
.net5,827 websites
.com.au5,125 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-56276

Top websites that are affected by CVE-2024-56276. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Germany*,***
****************.com United States*,***
*******.com Netherlands*,***
******.com United States*,***
******.com United States*,***
***********************.com United States*,***
*******.com United States*,***
*******.org Germany*,***
*************.com United States*,***
****.bg Bulgaria*,***
See full domain list

FAQ

CVE-2024-56276 is Missing Authorization in WPForms
A total of 268,820 websites have been identified as vulnerable to CVE-2024-56276, based on global website indexing conducted by WebTechSurvey.
The WPForms is affected by the CVE-2024-56276 vulnerability.
WPForms versions up to and including 1.9.2.2 are vulnerable to CVE-2024-56276.