Impact
The vulnerability allows an attacker to manipulate user‑controlled keys to bypass authentication checks, erroneously granting access to data or functionality that should be protected. Based on the description, the primary result is the ability to retrieve or modify sensitive information that the subject should not have access to. This weakness is classified as CWE‑639, highlighting a flaw in how the application verifies permissions for each request.
Affected Systems
HT Plugins: Extensions For CF7, all releases up to version 3.4.0 are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely a web‑based IDOR that requires the attacker to modify parameters in HTTP requests; the description does not specify remote code execution or automated exploitation, so it is inferred that the attacker needs to craft requests that may be sent from a browser or API client. The impact is limited to unauthorized access rather than full system compromise.
OpenCVE Enrichment