Impact
This vulnerability is an unauthenticated broken access control flaw in the FormyChat WordPress plugin versions up to 2.15.7. It allows attackers without credentials to perform privileged operations via plugin endpoints, as it fails to enforce proper access control. The weakness is classified as CWE‑862, indicating a failure to properly enforce access control. Based on the description, it is inferred that unauthorized users can trigger privileged plugin actions.
Affected Systems
The affected product is the WordPress FormyChat plugin (reported as WPPOOL:FormyChat) in all releases through and including version 2.15.7. Any WordPress site that has this plugin installed and has not been updated beyond 2.15.7 is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity and the vulnerability is exploitable without authentication. Based on the description, it is inferred that attackers can exploit it via HTTP requests to plugin‑specific URLs. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so no public exploit data is currently known. Nonetheless, because the flaw allows any internet user to perform privileged operations, the risk is significant, especially for sites with sensitive data or active user interactions facilitated by the plugin.
OpenCVE Enrichment