The Country State City Dropdown CF7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tc_csca_patch_settings function in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with subscriber access and above, to add states or cities to the dropdown.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Country State City Dropdown CF7 <= 2.7.1 - Missing Authorization | |
| Weaknesses | CWE-862 |
Thu, 26 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:34:20.576Z
Reserved: 2024-04-09T16:17:04.416Z
Link: CVE-2024-3520
Updated: 2024-08-01T20:12:07.603Z
Status : Awaiting Analysis
Published: 2024-05-02T17:15:26.420
Modified: 2026-04-08T17:18:43.113
Link: CVE-2024-3520
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:41Z