Impact
The vulnerability allows a logged‑in administrator to have form entries removed without their consent. By omitting the CSRF nonce, the plugin does not verify the request and it also lacks any capability check, so a crafted page that the admin visits triggers a delete operation on arbitrary entries. The result is loss of data integrity and availability of the form records.
Affected Systems
WordPress sites running the Database Addon for WPForms plugin before version 1.1.1 are affected. The plugin stores form submission records and the vulnerability lies in its entries management module.
Risk and Exploitability
The CVSS score is not listed in the source, but the lack of CSRF protection and missing capability verification give a moderate to high risk for authenticated administrators. An attacker must be able to lure an admin into loading a crafted URL. No public exploits have been reported and the EPSS score is unavailable, but the vulnerability is still exploitable under the described conditions. The plugin is not listed in the CISA KEV catalog.
OpenCVE Enrichment