Impact
The Easy Form plugin (Ays Pro:Easy Form) suffers from a missing authorization check, allowing attackers to bypass configured access control levels and potentially view or modify form data and configuration settings that should be restricted. Key detail from the CVE description: "Missing Authorization vulnerability ... allows Exploiting Incorrectly Configured Access Control Security Levels." This flaw is identified as CWE-862: Missing Authorization.
Affected Systems
All installations of the Easy Form plugin from any prior version up through 2.7.9 are affected. Key detail from vendor product information: "Easy Form: from n/a through <= 2.7.9." The specific affected version list is not provided, so any release ≤ 2.7.9 must be considered vulnerable.
Risk and Exploitability
The vulnerability has a moderate CVSS score of 5.3, and the EPSS score is below 1%, indicating a low current probability of exploitation. It is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. The likely attack vector is remote via the web interface and requires an attacker to exploit the missing authorization check on form-related endpoints. This assessment is inferred from the nature of the flaw and typical WordPress plugin attack surfaces.
OpenCVE Enrichment