Impact
A missing authorization flaw in the PDF for WPForms plugin allows users with any access level to execute arbitrary shortcodes. Because the plugin does not enforce proper access control, an attacker can embed a malicious shortcode that may turn into executable code, enabling the injection of custom PHP or other code into the website. The weakness is classified as CWE‑862, signifying insufficient authorization.
Affected Systems
The vulnerability affects the PDF for WPForms add‑on by add‑ons.org. All releases up to and including version 5.3.0 are affected. No later releases are listed as compatible with the flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity and the EPSS score of less than 1% suggests that the likelihood of current exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the content editor: any user with content creation or editing rights can insert the malicious shortcode, circumventing the intended access restrictions and potentially executing arbitrary code.
OpenCVE Enrichment
EUVD