Impact
The Vikas Ratudi VPSUForm VForm plugin suffers a missing authorization flaw that lets an attacker use or manipulate functionality that should be restricted. Because the plugin fails to enforce proper access control, unauthenticated or lower‑privilege users can exploit the exposed endpoints, potentially altering data or settings and affecting the confidentiality, integrity, and availability of the WordPress site.
Affected Systems
WordPress sites running the VPSUForm VForm plugin, versions up to and including 3.0.5. Any instance that has not been updated past this point is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely web‑based, requiring the attacker to send crafted HTTP requests to the plugin’s endpoints without proper role checks. Because the flaw is a broken access control issue, the risk is primarily to unauthorized configuration changes or data manipulation rather than remote code execution.
OpenCVE Enrichment
EUVD