Impact
The MetForm WordPress plugin before version 4.3.1 fails to enforce access controls on its REST API endpoints, enabling attackers to retrieve submission data without authentication. This flaw permits non‑privileged users to view potentially sensitive information entered through the form, compromising confidentiality of user data. The weakness is a classic authorization bypass, allowing unauthorized read access to protected resources.
Affected Systems
WordPress sites that use the MetForm plugin with a version earlier than 4.3.1 are impacted. The vulnerability is tied to the plugin itself, not to specific WordPress core versions; any site deploying the affected plugin is exposed.
Risk and Exploitability
The flaw can be exploited remotely by issuing simple REST API requests from any network accessible to the site, as no authentication is required. No specific exploit chain or additional preconditions are mentioned. The EPSS score of <1% indicates a low probability of exploitation, and the CVSS score of 5.3 reflects a moderate severity. The vulnerability is not listed in CISA KEV, but since it involves unauthenticated data disclosure it carries a non‑negligible risk, especially for sites that collect sensitive information.
OpenCVE Enrichment