Impact
The vulnerability is a missing authorization flaw that allows users to interact with or modify forms in the Calculated Fields Form plugin without proper permission checks. The flaw is characterized as a Missing Authorization weakness (CWE‑862) and can enable unauthorized creation, alteration, or deletion of forms, potentially exposing sensitive form data or allowing non‑admin users to manipulate form behavior. This could compromise confidentiality and integrity of form data stored by the site.
Affected Systems
The issue affects the WordPress Calculated Fields Form plugin from an unspecified initial release through version 5.4.4.1, as supplied by the vendor codepeople. Any installation of the plugin at or below this version is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve authenticated users who acquire access through the web interface and bypass the plugin’s normally restrictive access controls. Since no privilege escalation or remote code execution is described, the impact is limited to misuse of form functionality rather than system compromise.
OpenCVE Enrichment