Impact
The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plug‑in for WordPress allows unauthenticated users to retrieve the full file system path of the web application. This disclosure can assist attackers in mapping the environment and planning subsequent attacks, though the information itself is not actionable without another vulnerability. The weakness is categorized as CWE-200, where sensitive system information is exposed.
Affected Systems
All releases of the Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms by crmperks up to and including version 1.4.4 are affected. The plugin is distributed through the WordPress plugin repository and is installed on WordPress sites that use any of the supported form platforms.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1 percent shows a low probability of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an unauthenticated attacker to access the plugin’s disclosure endpoint; further damage would depend on the presence of additional weaknesses on the target site.
OpenCVE Enrichment
EUVD