Impact
The WS Form LITE WordPress plugin, in versions prior to 1.11.8, lacks an authorization check for a settings‑update action, an instance of CWE‑284: Improper Access Control. Authenticated users who possess subscriber privileges or higher can therefore modify plugin configuration values, even without administrative permissions. This capability can alter form handling, data persistence, or other plugin behaviours, potentially degrading site functionality or enabling covert data manipulation.
Affected Systems
WordPress sites running WS Form LITE plugin versions older than 1.11.8 are affected. The flaw resides in the plugin core and applies to all installations using those versions, hosting environment.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk; the EPSS score of < 1% shows a very low but non-zero exploitation probability, and there is no KEV listing. Because the vulnerability main attack vector likely involves a legitimate subscriber account, possibly through standard WordPress login or single‑sign‑on mechanisms. The impact is limited to configuration integrity but can be leveraged to further compromise the site if additional vulnerabilities exist.
OpenCVE Enrichment