Impact
Missing Authorization vulnerability in the Shahjada Live Forms plugin allows an attacker to bypass standard permission checks and gain access to form management functions. This broken access control can expose sensitive submission data and enable modification or deletion of forms. The weakness is categorized as CWE-862.
Affected Systems
WordPress sites using the Shahjada Live Forms plugin version 4.8.5 or earlier are affected. All installations of the plugin from its initial release through 4.8.5 lack proper permission checks.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity impact, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers may first identify vulnerable sites by searching for the plugin and then exploit the missing authorization flaw to access administratively protected form functions, potentially exposing user data or manipulating existing submissions.
OpenCVE Enrichment
EUVD