Impact
A missing authorization control in ThemeHunk Contact Form & Lead Form Elementor Builder allows an attacker to perform actions without proper authentication, resulting in unauthorized data modification or other privileged operations. The weakness is classified as CWE‑862, improper authorization, which can lead to a breach of confidentiality, integrity, and availability of the affected site.
Affected Systems
The vulnerability affects the WordPress plugin "Contact Form & Lead Form Elementor Builder" (ThemeHunk) with all releases up to and including version 1.8.4. Users of earlier versions are also potentially impacted if the same code path is present.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the web interface, possibly exploiting a CSRF or unauthenticated request to plugin endpoints, and does not require any special privileges to begin the attack.
OpenCVE Enrichment