Impact
Missing authorization in Funnelforms Free allows an attacker to perform privileged actions without proper access controls. The vulnerability can lead to unauthorized configuration changes, data exposure, or administrative control within the plugin, compromising the confidentiality and integrity of the WordPress site.
Affected Systems
The vulnerability affects the Funnelforms Free plugin for WordPress, specifically all releases up to and including version 3.8. WordPress sites that have not upgraded beyond this version with the plugin installed are at risk.
Risk and Exploitability
Based on the description, it is inferred that an attacker can exploit the broken access control by accessing administrative pages or functions of the plugin without proper authentication. The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog, and no official patch release is specified in the provided data.
OpenCVE Enrichment