Impact
A missing authorization flaw in the wishfulthemes Email Capture & Lead Generation plugin allows an attacker to bypass intended access controls, potentially enabling the execution of administrative actions or the viewing of sensitive data. This defect is categorized as a Broken Access Control weakness (CWE-862).
Affected Systems
The vulnerability affects all installations of the Email Capture & Lead Generation plugin, version 1.0.2 and earlier, by wishfulthemes.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the general population. The plugin is not listed in the CISA KEV catalog. The flaw is likely exploitable through a web-based interface, such as the WordPress admin panel or a REST endpoint, by accessing resources that rely on the plugin without proper user authentication. Without remediation, an attacker could gain unauthorized access to plugin features and data.
OpenCVE Enrichment
EUVD