Impact
The vulnerability arises from a missing authorization check in the WP Subscription Forms PRO plugin. This flaw allows an attacker to delete arbitrary content within the WordPress site, leading to loss of data and potential disruption of site functionality. The weakness is identified as CWE-862, an exposure of privileged commands to unauthorized users.
Affected Systems
The issue affects installations of WP Subscription Forms PRO by wpshuffle with a version of 2.0.5 or earlier. No specific release beyond 2.0.5 is known to be affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity overall, and the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Although the description does not explicitly state the attack vector, it is inferred that an attacker would need to access the plugin’s administrative interface, likely through authenticated WordPress sessions, to exploit the flaw.
OpenCVE Enrichment
EUVD