Impact
The vulnerability is a missing authorization flaw in the WordPress Gutenverse Form plugin. The plugin’s configuration and form data can be accessed or modified by users who should not have that level of privilege. An attacker could read sensitive form submissions or alter form behavior, potentially exposing private information or skewing data collection. This is a typical broken access control problem identified as CWE‑862.
Affected Systems
The flaw affects Jegstudio's Gutenverse Form plugin version 2.3.1 and any earlier releases. WordPress sites that have installed this plugin and have not updated to a newer version are susceptible. The vulnerability does not appear to impact other plugins or the core WordPress platform directly.
Risk and Exploitability
The CVSS score is 6.5, placing it in the medium severity range. The EPSS score is less than 1%, indicating a low likelihood that exploit activity is occurring at this time, and it is not listed in CISA’s KEV catalog. Attackers would need web access to the site and the ability to target the plugin’s backend or frontend interfaces; the flaw is exploited by leveraging incorrect or missing authorization checks, so no special credentials are required beyond those normally granted to site editors or lower‑privileged users.
OpenCVE Enrichment