Impact
The Happyforms – Form Builder for WordPress plugin contains a local file inclusion flaw (CWE‑98) in the happyforms_get_form_partial() function. An authenticated user with administrator level or higher privileges can supply the path to an arbitrary .php file, causing the server to include and execute that file. This allows the attacker to run arbitrary PHP code, bypass access controls, read sensitive files, or otherwise compromise the.
Affected Systems
Any WordPress installation that has the Happyforms plugin version 1. exists in all releases up to and including 1.26.12 and is not limited by WordPress core version.
Risk and Exploitability
The CVSS score of 6.6 denotes moderate severity, while the EPSS score of less than that the likelihood of public exploitation is currently low. Because the flaw requires administrator or higher privileges and the ability to place a malicious .php file on the server, it is typically confined to environments where such access exists. The vulnerability is not listed in CISA KEV, and no public exploits are known at this time. When both conditions are met, an attacker can execute code and potentially gain full server compromise.
OpenCVE Enrichment