Impact
The Gutena Forms plugin versions up to 1.9.0 contain an unauthenticated broken authentication flaw that allows an attacker to bypass the plugin’s login controls and gain privileged access. This vulnerability is classified as CWE‑288 and can enable the attacker to view, modify, or delete form configurations, and potentially retrieve sensitive data submitted through the embedded forms.
Affected Systems
WordPress sites that have installed the Gutena Forms plugin by Saad Iqbal, specifically any version 1.9.0 or earlier. All attacks target the plugin’s administrative interface, which is exposed to all visitors of the site.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate risk. Because the flaw permits unauthenticated exploitation via the web interface, the attack vector is remote and does not require the attacker to possess any existing credentials. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified, but the public availability of the plugin and the lack of authentication checks provide a wide attack surface. The vulnerability is not currently listed in the CISA KEV catalog, reducing the visibility to security teams that rely on that feed. Nonetheless, the ease of exploitation and moderate severity warrant prompt remediation.
OpenCVE Enrichment