Impact
The vulnerability in the Contact Form to Chat Apps plugin allows unauthenticated users to retrieve any form submission that has been created using Gravity Forms or other supported third‑party form integrations. Because the formychat_get_gf_entry AJAX action does not verify capability, nonce or session data, an attacker can craft a request to the endpoint and read sensitive fields such as names, email addresses and custom data. This results in a loss of confidentiality for all data collected through the plugin. The weakness is identified as information disclosure (CWE‑200).
Affected Systems
Any WordPress site that has the Contact Form to Chat Apps plugin older than 2.15.8 with Gravity Forms or compatible form providers enabled is at risk. The vulnerability is independent of the user’s role because no authentication is checked.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as moderate severity. The EPSS score of 0.00206 indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation yet. However, the lack of authentication and public AJAX endpoint makes the attack trivial for any internet‑reachable user; an attacker can issue an unauthenticated HTTP request to the plugin’s endpoint and obtain the form entries without further prerequisites.
OpenCVE Enrichment