Impact
The Gutena Forms WordPress plugin is affected by a missing authorization check in the save_gutena_forms_schema() function. Attackers who have Contributor-level access or higher can modify form schema settings. This enables them to change options such as site registration or create configuration errors that deny service to legitimate users. The flaw allows unauthorized data modification that impacts the website’s configuration and functionality.
Affected Systems
All WordPress sites running Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder versions 1.6.0 or earlier are vulnerable. The risk applies to users with Contributor role or higher access who can edit form settings.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity. EPSS <1% indicates a low probability of exploitation. The issue is not listed in the KEV catalog. Exploitation requires an authenticated contributor or higher role in WordPress; the attacker can then adjust plugin options to cause a site outage or enable unwanted feature settings.
OpenCVE Enrichment