Impact
The vulnerability is a missing authorization flaw that allows incorrectly configured access control to be exploited in the Icegram Collect plugin. Attackers can use this flaw to gain unauthorized access to lead collection data and perform actions that should be restricted. This flaw maps to CWE‑862, representing improper authorization.
Affected Systems
Affecting the Icegram Collect WordPress plugin from version 1.3.18 and earlier. The plugin is distributed under the name Icegram Collect by Icegram: Icegram Collect. Users running any of these versions are potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk, but the EPSS score of < 1% shows a low likelihood of exploitation currently. The issue is not listed in CISA KEV, so no known public exploitation. The likely attack vector is through a remote HTTP request to the plugin’s endpoints, inferred from the nature of the plugin handling form submissions. If an attacker can reach the plugin without proper authentication, they may read, modify or delete lead information, thereby compromising confidentiality and integrity of lead data.
OpenCVE Enrichment
EUVD