Impact
The WP Forms Signature Contract Add‑On contains a missing authorization flaw that permits an attacker to dismiss notices that should be protected by appropriate access controls. The vulnerability arises from incorrectly configured security levels that do not validate the user's permission before performing the dismissal action, aligning with CWE‑862.
Affected Systems
The flaw affects the approveme WP Forms Signature Contract Add‑On plugin in all releases up to and including version 1.8.2. Any WordPress installation that has this plugin installed and configured is vulnerable, regardless of other plugins or themes.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate risk level. The EPSS score is less than 1 %, implying the likelihood of exploitation is very low at present. This vulnerability is not listed in the CISA KEV catalog. Based on the description, an attacker could exploit the flaw by sending a request that triggers the notice‑dismissal action in the WordPress site that has the plugin installed, taking advantage of the missing authorization check.
OpenCVE Enrichment