Impact
The vulnerability arises from a missing capability check on multiple AJAX actions within the Easy Form Builder plugin. A logic error causes the plugin to combine the checks with AND instead of OR, resulting in a bypass of the intended authorization. As a consequence, any authenticated user with a Subscriber role or higher can recover private form response data such as submissions, administrator replies, and user identifiers, which constitutes a confidentiality compromise.
Affected Systems
WordPress sites running the Easy Form Builder plugin by WhiteStudio, version 3.9.3 or earlier, are affected.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Attackers must first be authenticated with Subscriber-level access or higher and can then issue AJAX calls to retrieve the data. No external network exposure or code execution is required for exploitation.
OpenCVE Enrichment