Impact
The vulnerability is a broken access control flaw (CWE‑862) that permits a subscriber‑level user to carry out operations that should only be available to higher‑. Attackers can access or modify data within the plugin, potentially exposing sensitive information or altering form behavior. The description does not specify the exact actions that can be performed beyond their permissions, but the impact is that confidentiality and integrity of the data handled by the plugin can be compromised.
Affected Systems
WordPress sites that use the Advanced Contact form 7 DB plugin from Vsourz Digital, specifically versions 2.0.9 and earlier. The flaw was addressed in version 2.1.0 and later releases.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. With an EPSS score of less than 1%, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KE on the description, the likely attack vector is an authenticated subscriber account leveraging the plugin’s administrative endpoints to perform actions outside the intended role scope.
OpenCVE Enrichment