Impact
The CVE details a missing authorization flaw in WesternDeal's CF7 Google Sheets Connector plugin that allows attackers to bypass intended access controls. This weakness, classified as CWE-862, can enable users to perform actions on the site that they are not authorized to do, such as manipulating form data or retrieving sensitive information stored via the Google Sheets integration.
Affected Systems
The vulnerability affects the WordPress CF7 Google Sheets Connector plugin, specifically versions up to and including 5.0.17. The affected product is published by WesternDeal and is used within the WordPress ecosystem.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation based on current model predictions. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is likely to occur through the plugin's exposed endpoints or configuration pages, whereby an authenticated user with limited privileges can leverage the missing checks to gain broader access to data or functionality tied to the Google Sheets integration.
OpenCVE Enrichment
EUVD