Impact
This vulnerability is a missing authorization flaw that lets attackers bypass the plugin’s configured access control levels. Because the plugin does not enforce proper permission checks, an attacker can read or modify registration forms or submission data that should be restricted to administrators. The flaw is classified under CWE‑862 and can compromise the confidentiality and integrity of user data.
Affected Systems
All WordPress sites that have the Metagauss RegistrationMagic custom‑registration‑form‑builder‑with‑submission‑manager plugin installed at a version of 6.0.7.6 or earlier are affected. The issue applies regardless of other security measures in place, as it originates in the plugin code.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level, while the EPSS score of less than 1% suggests that exploitation is unlikely but still possible. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could exploit this flaw by sending crafted HTTP requests to the plugin’s endpoints from any remote location, making the attack vector remote via the web. No additional prerequisites are stated, so any external user with internet access to the affected site could potentially target the weakness.
OpenCVE Enrichment