Impact
Unauthenticated users can bypass the authentication checks implemented by the WordPress Contact Form by Supsystic plugin in versions older than 1.10.0, allowing them to submit form data without proper authorization. The flaw represents a failure to enforce authentication or authorization policies, as identified by CWE-288.
Affected Systems
Any WordPress installation that has the Contact Form by Supsystic plugin installed with a version older than 1.10.0 is affected. The plugin may be present on public‑facing sites that expose contact forms and allow external users to interact with them.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is not yet widespread. Attackers can craft requests against the form endpoint to trigger the bypass, resulting in unauthorized form submissions.
OpenCVE Enrichment