Impact
The vulnerability allows an unauthenticated user to export entries from Gravity Forms through the GravityExport Lite plugin. This broken access control does not facilitate code execution but permits bypassing all permission checks, exposing potentially sensitive user submissions to the public.
Affected Systems
Any WordPress site running GravityExport Lite for Gravity Forms version 2.7.2 or older is affected. The plugin is provided by GravityKit and is identified by the product name GravityExport Lite for Gravity Forms.
Risk and Exploitability
The CVSS score of 7.5 reflects a high impact, and the EPSS score is not available, so the exploitation likelihood is uncertain but could be significant given the lack of authentication requirement. The vulnerability is not listed in the CISA KEV catalog, but the absence of a patch for older versions means attackers can freely exploit the flaw if the site has not applied the latest update.
OpenCVE Enrichment