Impact
The vulnerability is a broken access control flaw in the FormGent plugin for WordPress, allowing unauthorized users to perform actions reserved for subscribers. If exploited, an attacker could create, modify, or delete subscriber data without proper authentication, potentially exposing sensitive information or disrupting site functionality. This weakness is identified as CWE-862, Improper Access Control.
Affected Systems
This issue affects installations of the wpWax:FormGent plugin version 1.12.2 and earlier. The plugin is a popular form management tool for WordPress sites. Users running these versions without upgrading are exposed.
Risk and Exploitability
The recorded CVSS score is 7.1, indicating a moderate risk level. EPSS is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA's KEV catalog, suggesting no known large-scale exploitation. The attack vector is inferred to be remote via the public form endpoints, as the issue involves broken access control, so an attacker with web access could trigger the flaw by manipulating form requests.
OpenCVE Enrichment