Impact
Unauthenticated Broken Access Control in JetFormBuilder plugin versions up to 3.6.4.1 allows an attacker to perform actions normally restricted to privileged users, such as creating, editing, or deleting forms. This can result in unauthorized data exposure, alteration, or loss, and potentially serve as a foothold to further compromise the WordPress site. The vulnerability is categorized as CWE-862, indicating improper enforcement of access control policies.
Affected Systems
The affected product is JetMonsters JetFormBuilder plugin for WordPress. Versions up to 3.6.4.1 are impacted. No other products or versions are listed in the current advisories.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. While the EPSS score is not available, the absence of a listing in CISA KEV suggests that exploitation is currently not widespread, yet the high CVSS indicates significant potential damage if discovered and exploited. The attack vector is inferred to be unauthenticated access to the WordPress site, taking advantage of the plugin's lack of proper authorization checks.
OpenCVE Enrichment