Impact
Gravity Booster – Styles & Layouts for Gravity Forms plugin is vulnerable to broken access control, permitting a subscriber role user to perform actions beyond their intended permissions. This flaw could allow the attacker to alter form layouts, settings, or injected content, potentially exposing or manipulating sensitive data handled by the plugin. The primary consequence is unauthorized configuration changes that could compromise data integrity and availability within the website.
Affected Systems
The vulnerability affects the WordPress plugin Gravity Booster – Styles & Layouts for Gravity Forms released by wpmonks, versions 6.0 and earlier. No additional version details are supplied; all releases up to and including 6.0 are impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, so the current exploitation probability cannot be precisely quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw through the web interface by sending authenticated requests as a subscriber; the likely attack vector is network-based HTTP/S. Due to the lack of a public exploit, immediate risk is moderate but should be mitigated promptly.
OpenCVE Enrichment