Impact
The vulnerability is an unauthenticated broken access control flaw affecting the WordPress Post My CF7 Form plugin up through version 6.2.0. Because the plugin does not enforce proper user permissions, an attacker can perform actions reserved for privileged users, such as viewing, modifying, or deleting form submissions, or altering plugin configuration. This weakness is classified as CWE‑862 and can compromise the confidentiality and integrity of data collected by the form.
Affected Systems
The affected product is the Post My CF7 Form plugin developed by Aurovrata Venet. All releases with a version number of 6.2.0 or earlier are vulnerable. The flaw impacts the entire plugin code base, so any WordPress site that has not applied the latest version is at risk.
Risk and Exploitability
The CVSS score of 7.5 reflects high severity because no authentication is required for exploitation. The EPSS score is extremely low (<1 %) and the vulnerability is not listed in CISA’s KEV catalog, suggesting no public exploitation yet. The likely attack vector is the web interface: an attacker can send crafted HTTP requests to the plugin’s endpoints without logging in, allowing arbitrary access to privileged actions which could lead to data exfiltration or further compromise of the site. The overall risk remains significant due to the potential for unauthorized data access and configuration changes.
OpenCVE Enrichment