Impact
The JetFormBuilder plugin for WordPress contains a missing authorization flaw that allows attackers to bypass access controls and exploit incorrectly configured security levels. This weakness, classified as CWE-862, enables an unauthorized user to perform actions beyond the intended role, potentially exposing, altering, or deleting form data or configuration. Although the CVSS score of 5.3 indicates moderate severity, the vulnerability still threatens the confidentiality and integrity of user-submitted information and the overall reliability of the form handling feature.
Affected Systems
The vulnerability affects the JetFormBuilder plugin by jetmonsters, impacting all installations running version 3.5.3 or earlier. The issue applies from the earliest available version through to and including 3.5.3.
Risk and Exploitability
The EPSS score of less than 1% suggests a low probability of real-world exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Nevertheless, the attack vector is likely remote, occurring via standard HTTP requests to form endpoints where access checks are omitted. An attacker with even low or no site permissions could potentially exploit this flaw, subject to how the plugin’s permissions are configured.
OpenCVE Enrichment