Impact
This vulnerability is an insecure direct object reference that lets an attacker obtain data belonging to other users by manipulating a user-controlled key. The issue is classified as CWE-639, indicating that access control is bypassed. An exploited instance can read sensitive information or administrative data that the attacker should not have permission to view, potentially revealing configuration details, personal data, or other confidential content from the WordPress site.
Affected Systems
The affected product is the Brainstorm Force SureForms plugin for WordPress, specifically all versions from the first release through 2.12.5, inclusive. No other vendors or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, reflecting that the flaw requires authenticated or possibly unauthenticated access to malformed requests. The EPSS score is not available, and the vulnerability has not been catalogued in the CISA KEV list. The likely exploitation path is a crafted HTTP request that targets the plugin’s endpoints, substituting a valid key or ID to retrieve records owned by other users. No additional prerequisites are noted beyond the ability to send requests to the site, making the attack vector fairly straightforward for an attacker with access to the network or the public-facing web application.
OpenCVE Enrichment