Impact
This vulnerability arises from improper enforcement of access controls in the RomethemeForm For Elementor plugin. The flaw allows an attacker who can reach the plugin’s interface to bypass normal authorization checks and manipulate or retrieve form data, settings, or execute unintended actions. The impact is primarily a breach of confidentiality and integrity for form submissions and a potential elevation of privileges within the WordPress installation.
Affected Systems
The affected product is the RomethemeForm For Elementor plugin from the rometheme vendor, with all releases up to and including version 1.2.6 being vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. Because the plugin is web‑exposed and the flaw involves access‑control checks, the likely attack vector is remote, requiring the attacker to authenticate or gain access to a user account with sufficient privileges. No special conditions or advanced skills are explicitly required beyond the knowledge of the vulnerable endpoint.
OpenCVE Enrichment