WordPress Plugin Vulnerabilities

Forminator < 1.24.1 - Unauthenticated Race Condition on poll vote

Description

The plugin does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.

Proof of Concept

Affects Plugins

Fixed in 1.24.1

References

Classification

Type
RACE CONDITION
CWE

Miscellaneous

Original Researcher
Amirmohammad vakili
Submitter
captain_hook
Verified
Yes

Timeline

Publicly Published
2023-06-12 (about 2 years ago)
Added
2023-06-12 (about 2 years ago)
Last Updated
2023-06-12 (about 2 years ago)

Other