Impact
The WordPress plugin suffers from a missing capability check in the rednumber_duplicate function, allowing authenticated users with Subscriber-level access or higher to duplicate any post, including those that are password protected or private. This flaw enables the creation of duplicate entries without proper authorization and can lead to accidental exposure of confidential content, manipulation of site data, and potential flooding of the site with redundant posts.
Affected Systems
All installations of PDF for Contact Form 7 + Drag and Drop Template Builder running versions 6.3.3 and earlier, which is a plugin for the WordPress content management system.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to be logged in with a Subscriber role or above; no elevated privileges are required. Exploitation requires the missing authorization check to be triggered when a user invokes the duplication function.
OpenCVE Enrichment