Impact
Missing authorization in the Mailercloud – Integrate webforms and synchronize website contacts plugin allows attackers to use endpoints that should be restricted to privileged users, enabling unauthorized modifications or disclosure of contact data.
Affected Systems
The vulnerability affects the Mailercloud – Integrate webforms and synchronize website contacts plugin in all releases up to and including version 1.0.7.
Risk and Exploitability
Because the plugin omits proper authorization checks, an attacker with any access to the WordPress site can issue requests to privileged API endpoints and gain the same capabilities as an administrator for contact data. The flaw can be exploited entirely via the web interface without additional system compromise. Although no CVSS or EPSS metrics are published, the possibility of full unauthorized data access and modification makes the risk high, warranting immediate attention.
OpenCVE Enrichment