Impact
The Advanced Form Integration – Connect Forms to 200+ Apps plugin fails to enforce role restrictions when creating a WordPress user from a public form submission. An attacker can submit a crafted form that maps a selected field to a user role, creating a new account with administrative privileges. This flaw effectively allows an unauthenticated visitor to gain full control of the site, compromising confidentiality, integrity, and availability. The issue reflects an improper authorization weakness (CWE-284).
Affected Systems
This vulnerability impacts any WordPress installation that has the Advanced Form Integration plugin at a version earlier than 2.1.1. It requires that an active integration maps a role‑setting field to a public form field; if that condition is present, an unauthenticated request can generate an account with the mapped role.
Risk and Exploitability
The CVSS score of 8.1 marks the flaw as high severity, and the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need only to submit a form payload to a public form that is role‑mapped; no authentication or special privileges are required. The resulting privilege escalation would give the attacker full administrative authority over the affected WordPress site.
OpenCVE Enrichment