Impact
The Advanced Forms plugin contains a missing authorization flaw that permits users to bypass the plugin’s configured access control levels, potentially exposing or altering sensitive form data. This problem is identified as a classic authorization bypass and is catalogued as CWE‑862.
Affected Systems
WordPress sites that have the Phil Kurth Advanced Forms plugin installed at version 1.9.3.7 or earlier are affected. The vulnerability applies to all releases of the plugin released up to and including that version.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity. Its EPSS score is less than 1%, implying a low current exploitation probability, and it is not listed in the CISA KEV catalog. The likely attack vector is remote, using the plugin’s exposed administrative or form‑submission interfaces, though specific prerequisites are not detailed in the description and are therefore inferred.
OpenCVE Enrichment