Impact
A missing authorization check in the approveme Signature Add‑On for Gravity Forms allows an attacker to act with the privileges of any user that can access the plugin’s endpoints, potentially reading, modifying, or deleting signatures collected by Gravity Forms. The vulnerability maps to CWE‑862, a broken access control weakness that can compromise the confidentiality and integrity of data submitted through the form.
Affected Systems
WordPress sites that have the approveme Signature Add‑On for Gravity Forms installed at any version through 1.8.6 are at risk. This includes all installations that have not yet applied an upgrade beyond that version.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, while an EPSS score of less than 1% suggests that this flaw is currently unlikely to be widely exploited. The flaw is not listed in the CISA KEV catalog. An attacker would need to send crafted requests to the plugin’s exposed URLs, possibly leveraging authenticated sessions or weak user permissions. Because the flaw permits bypassing normal access controls, the risk to affected sites is primarily to the integrity and availability of collected signature data.
OpenCVE Enrichment