Impact
The vulnerability is a missing authorization flaw that allows a user to perform actions within the WPForms Google Sheet Connector beyond those intended for their role. This broken access control can enable an attacker to read, modify, or delete the data that the plugin forwards to Google Sheets, potentially exposing sensitive business information. The weakness is classified as CWE-862, which indicates improper authorization handling.
Affected Systems
WesternDeal WPForms Google Sheet Connector plugin versions up to and including 4.0.0 are affected. Any WordPress installation that has this plugin installed and activated falls within the scope of the vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be through the WordPress administrative interface; an authenticated user with insufficient privileges could attempt to access or modify connector configurations. No public exploitation evidence is currently available, but the flaw could be leveraged by attackers who gain access to a site’s backend or through social engineering to elevate privileges.
OpenCVE Enrichment