Impact
The AutomatorWP WordPress plugin has a missing authorization check that allows any authenticated user with subscriber or higher role to access an AJAX endpoint that returns database records from the Fluent Forms integration. An attacker can exploit this to list form IDs and titles, revealing internal application data and potentially aiding further reconnaissance or other attacks. The weakness is a classic authorization bypass (CWE‑862).
Affected Systems
WordPress sites running AutomatorWP version 5.8.4 or earlier, regardless of other installed plugins, are affected. The vulnerability originates in the ajax_functions.php file within the Fluent Forms integration of the plugin. Upgrading to AutomatorWP 6.0.3 or later removes the flaw.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a legitimate WordPress login with subscriber-level access and above; no special network exposure is needed aside from the normal site login interface. , the AJAX call can enumerate all forms, giving them a clear view of the site’s form architecture.
OpenCVE Enrichment