Impact
This bug is a missing Authorization flaw that allows an attacker to exploit incorrectly configured access control levels in the ZealousWeb Abandoned Contact Form 7 plugin. Because the plugin does not enforce proper role checks, users who would normally be denied can perform privileged actions, potentially reading or altering form settings and data. The described vulnerability could lead to data exposure or unauthorized configuration changes. The weakness maps to CWE‑862.
Affected Systems
The vulnerability affects ZealousWeb Abandoned Contact Form 7, version 2.2 and earlier. WordPress sites that have installed the plugin in any build from the initial release through version 2.2 are susceptible.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. The EPSS score of less than 1% shows a very low probability of exploitation in commercial attack lists, and the issue is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote web-based, where an unauthenticated or low‑privileged user interacts with the site’s plugin interface or submits crafted requests to manipulate form settings. The vulnerability can be exploited without additional system compromise, making it a straightforward privilege escalation flaw in the WordPress environment.
OpenCVE Enrichment
EUVD