Impact
The vulnerability is a missing authorization flaw in the Easy Form Builder plugin that allows attackers to bypass the intended access control checks. This broken access control means an unauthorized user could view, edit, or delete form submissions and potentially access other protected resources within the WordPress site. The weakness is classified as CWE‑862.
Affected Systems
The plugin named Easy Form Builder from hassantafreshi is affected for all releases from the earliest available version through 3.8.20 inclusive. No patch version information is provided in the CNA data, so all installations of 3.8.20 or older remain vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1 % suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers with access to the WordPress backend can exploit the flaw via the plugin’s administrative interface, potentially extracting sensitive form data or escalating privileges.
OpenCVE Enrichment