Impact
The flaw in PDF for WPForms is a missing authorization issue that allows an attacker to bypass properly configured access controls. The vulnerability enables the retrieval or viewing of PDF files that should be restricted, which compromises the confidentiality of the documents. The weakness is classified as CWE-862, indicating improper or missing authorization controls.
Affected Systems
Add‑ons.org's PDF for WPForms plugin with any installation version from the earliest available release through 5.5.0 is affected. No earlier fixed version is indicated in the data.
Risk and Exploitability
The CVSS score of 5.0 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. Attackers would need to submit requests to the plugin’s endpoints that bypass the authorization checks; based on the description, it is inferred that the attacker can do this remotely from outside the WordPress site. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD