Impact
The vulnerability is an unauthenticated Broken Access Control flaw in the ez Form Calculator Premium plugin that allows any visitor to invoke privileged plugin functions that should be restricted to authenticated users, potentially exposing sensitive information or modifying form behavior. This weakness is of access control policies.
Affected Systems
WordPress sites that use the Keksdieb ez Form Calculator Premium plugin version 2.14.1.2 or any earlier release are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of < 1 % suggests that exploitation is unlikely at present. The plugin is not listed in the CISA KEV catalog. Attackers would need to interact with the plugin over the network, most plausibly by forging HTTP requests that target plugin endpoints lacking proper authentication checks. This inference is based on the description that the vulnerability is unauthenticated, which typically exposes such endpoints via web requests.
OpenCVE Enrichment