CVE-2024-1306: Rednao Smart Forms

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as editing entries, and we consider it a medium risk.

Affected products

  • Rednao Smart Forms: before 2.6.94 (fixed in 2.6.94)

Published 2024-04-15. Last modified 2026-06-17.