Impact
The vulnerability is a missing authorization flaw in the Ali Khallad Contact Form By Mega Forms WordPress plugin. The flaw allows an attacker to bypass configured security levels and gain unauthorized access to protected functionality within the plugin. This can result in the attacker viewing, modifying, or deleting contact form data and potentially executing arbitrary actions provided by the plugin’s backend endpoints. The weakness is identified as CWE‑862, which corresponds to access control deficiencies.
Affected Systems
The defect is present in all released versions of the Ali Khallad Contact Form By Mega Forms plugin through and including version 1.6.1. Any WordPress site that has installed this plugin, regardless of the rest of the platform’s version, is potentially affected.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating a moderate level of risk. The EPSS score is below 1 %, showing that the probability of exploitation at the time of analysis is low. It is not listed in the CISA KEV catalog, so there is no documented widespread exploitation. Based on the description, the likely attack vector is through the plugin’s exposed web endpoints; an attacker may need to craft a request that bypasses normal authorization checks, potentially without requiring any user credentials. The exposure would allow excessive privilege escalation within the context of the plugin’s functionality.
OpenCVE Enrichment
EUVD