Impact
WPForms Lite WordPress plugin versions 1.5.0.1 through 2.0.2 contains a flaw where submitted form field values are written back into the page without removing shortcode delimiters. This omission lets any visitor, without authentication, insert and execute arbitrary shortcodes that are registered on the site. Because shortcodes can invoke plugin and core WordPress functions, an attacker could run code that reads or manipulates file attachments to non-public posts, exposing sensitive data. The weakness is a code injection type flaw with potential for information disclosure, as reflected by CWE‑94 and CWE‑200.
Affected Systems
The affected product is the WPForms Lite WordPress plugin. Vulnerable releases are any version from 1.5.0.1 up to and including 2.0.2. The vendor is WPForms, but the CNA lists it as Unknown:WPForms.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is unavailable, and the vulnerability is not listed in CISA KEV. Because the flaw allows unauthenticated users to craft a form submission, the likely attack vector is a simple HTTP POST request to the vulnerable form. No special privileges or local access are required, and exploitation does not appear to be dependent on other configuration weaknesses, making the risk significant for sites that keep the plugin at these versions.
OpenCVE Enrichment