Caldera Forms Pro <= 1.8.1 - Unauthenticated Arbitrary File Read
According to the vendor: "This update includes an important SECURITY fix that affects some Pro customers. If you do not have Caldera Forms Pro API keys activated, this issue does not affect you." According to the original researchers: "The Caldera Forms Pro vulnerability would allow attackers to read arbitrary files such as wp-config.php and leak database access credentials."
fixed in version 1.8.2
|Publicly Published||2019-03-07 (5 months ago)|
|Added||2019-03-11 (4 months ago)|
|Last Updated||2019-03-14 (4 months ago)|