Impact
The Tectite Forms plugin for WordPress contains a Cross‑Site Request Forgery flaw that allows an attacker to submit a forged HTTP request to the admin_init endpoint without any authentication. Because the nonce check is missing or incorrect, the attacker can modify any of the plugin’s settings, including the tectite_forms_button option. The impact is a unilateral alteration of plugin behavior that can change how forms appear or behave, potentially impacting site usability and the user experience, but does not directly lead to code execution or data exfiltration.
Affected Systems
All installations of the Tectite Forms plugin version 1.3 or earlier are vulnerable. The plugin is authored by russellr and runs within the WordPress environment; any site that has enabled this plugin and has logged‑in administrators that accept HTTP requests is affected.
Risk and Exploitability
With a moderate CVSS score of 4.3, the vulnerability is considered medium severity. The EPSS score is unavailable, and the issue is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by crafting a malicious link or form that, when clicked by a site administrator, initiates a forged request to the vulnerable endpoint and changes plugin settings. No user credentials are required, so the risk to any site with an active admin user is significant if the attacker can entice that user to interact with the crafted request.
OpenCVE Enrichment