Impact
WordPress Super Forms plugin versions up to 6.3.315 contain a flaw that allows an unauthenticated attacker to request any file that the web server can read via the plugin’s download endpoint. The vulnerability exposes server files without the need for credentials, potentially leaking sensitive data and giving attackers information useful for further attacks.
Affected Systems
All WordPress sites running Super Forms plugin 6.3.315 or earlier are affected. The issue is limited to the plugin and does not involve core WordPress or other plugins.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates high severity. The EPSS score is not available, and the vulnerability is not yet listed in CISA KEV. Exploitation requires only a standard HTTP GET request to the download URL, making remote exploitation straightforward for anyone with network access to the site.
OpenCVE Enrichment