Impact
The WS Form LITE WordPress plugin before version 1.11.8 does not perform an authorization check on a settings‑update action. Authenticated users who have subscriber privileges or higher can therefore modify the plugin’s configuration options. The weakness is improper access control. Based on the description, it is inferred that the unauthorized change could alter form handling logic and potentially affect how data is processed, but it does not directly provide code execution or other higher‑level privileges.
Affected Systems
WordPress installations that have the WS Form LITE plugin installed in any version older than 1.11.8 are vulnerable. The flaw resides in the plugin core and applies uniformly to all affected sites regardless of hosting environment or other configuration.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk level. The EPSS score of < 1% shows a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must possess an authenticated WordPress account with subscriber or greater permissions to exploit the flaw. Based on the description, it is inferred that the likely attack vector is the legitimate settings‑update endpoint exposed by the plugin. Based on the description, it is inferred that the impact is limited to configuration integrity and does not enable remote code execution or other severe compromise mechanisms.
OpenCVE Enrichment