Impact
Missing Authorization in PDF for WPForms plugin lets an attacker bypass intended access control and retrieve PDF content that should be restricted. Because the access levels are incorrectly configured, any content generated or stored by the plugin might be exposed to users without proper privileges. This flaw enables unauthorized access to documents, potentially compromising confidentiality.
Affected Systems
The vulnerability affects the PDF for WPForms plugin for WordPress from the earliest version through version 6.3.0. It is distributed by add‑ons.org and is installed as a plugin on WordPress sites. Any site running a vulnerable version of this plugin is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact. EPSS < 1% suggests low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is HTTP requests to the plugin’s exposed endpoints, allowing a user to exploit misconfigured access control settings. This inference is not directly stated in the input.
OpenCVE Enrichment