Description
The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings.
Published: 2026-07-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WS Form LITE WordPress plugin before version 1.11.8 does not perform an authorization check on a settings‑update action. Authenticated users who have subscriber privileges or higher can therefore modify the plugin’s configuration options. The weakness is improper access control. Based on the description, it is inferred that the unauthorized change could alter form handling logic and potentially affect how data is processed, but it does not directly provide code execution or other higher‑level privileges.

Affected Systems

WordPress installations that have the WS Form LITE plugin installed in any version older than 1.11.8 are vulnerable. The flaw resides in the plugin core and applies uniformly to all affected sites regardless of hosting environment or other configuration.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk level. The EPSS score of < 1% shows a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must possess an authenticated WordPress account with subscriber or greater permissions to exploit the flaw. Based on the description, it is inferred that the likely attack vector is the legitimate settings‑update endpoint exposed by the plugin. Based on the description, it is inferred that the impact is limited to configuration integrity and does not enable remote code execution or other severe compromise mechanisms.

Generated by OpenCVE AI on August 4, 2026 at 08:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WS Form LITE to version 1.11.8, which adds the missing capability check.
  • If an immediate upgrade is not possible, restrict the subscriber role and any lower levels from accessing or editing the plugin’s settings using a role‑management or capabilities plugin.
  • Disable the settings API of WS Form LITE or place the plugin in maintenance mode until a fix can be applied.

Generated by OpenCVE AI on August 4, 2026 at 08:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 03 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 25 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 22 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 12 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-862

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-862

Fri, 10 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Thu, 09 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Wed, 08 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-285

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-285

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 05 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-703

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-703

Thu, 02 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Wed, 01 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 01 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings.
Title WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-01T10:20:02.352Z

Reserved: 2026-06-08T07:53:35.591Z

Link: CVE-2026-11562

cve-icon Vulnrichment

Updated: 2026-07-01T10:19:58.639Z

cve-icon NVD

Status : Deferred

Published: 2026-07-01T07:16:21.993

Modified: 2026-07-01T18:17:52.013

Link: CVE-2026-11562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:15:06Z

Weaknesses