Impact
A missing authorization check in the Flo Forms plugin allows attackers to exploit incorrectly configured access control levels. The flaw can enable unauthorized users to gain access to plugin functionality or sensitive form data, potentially leading to data disclosure or manipulation within the WordPress site.
Affected Systems
The vulnerability affects the WordPress Flo Forms plugin from any version up to and including 1.0.43, provided by the vendor flothemesplugins. All WordPress sites running these versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a web-based request to the Flo Forms administration interface, where an attacker can attempt to access restricted functions without proper authorization.
OpenCVE Enrichment
EUVD