Impact
The vulnerability is a missing authorization flaw that permits accessing plugin functionality without proper checks. It is classified as CWE‑862 and allows users or attackers to invoke operations that should be limited by access control lists, resulting in unauthorized access to data or actions intended to be restricted within the WordPress site.
Affected Systems
All instances of the Salesmate Add‑On for Gravity Forms plugin distributed by Salesmate.io with versions up to and including 2.0.3 are affected. No other products or versions are listed as impacted, and the issue does not apply beyond the stated maximum version.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows that exploitation is currently considered very unlikely. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is web‑based, requiring interaction with the plugin's endpoints; based on the description it is inferred that an attacker would need access to the WordPress site or a valid user session, but no remote code execution or elevated privileges are explicitly required in the public description.
OpenCVE Enrichment
EUVD