Impact
An unauthenticated broken access control flaw exists in the Online Contact Widget plugin version 1.3.0 and earlier. Attackers can exercise functions reserved for authorized users, such as altering contact form settings or accessing stored messages, thereby compromising the integrity of the site’s communication features.
Affected Systems
WordPress sites that have installed the Online Contact Widget plugin from wbolt.com at version 1.3.0 or earlier are affected. Any instance that has not yet been upgraded remains vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 places this vulnerability in the medium to high severity range. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be through the plugin’s web interfaces, which can be accessed without authentication, meaning an attacker only needs to send requests to the relevant URLs. Because the flaw allows unauthenticated users to perform privileged actions, the risk to site integrity and confidentiality is significant.
OpenCVE Enrichment