WS Form LITE
cpe:2.3:a:westguardsolutions:ws_form:*:*:*:*:wordpress:*:*
- <= 1.10.35
A vulnerability exists in the WS Form LITE WordPress plugin, specifically in versions through 1.10.35. The issue arises from a missing capability check in the 'get_config' function, which is part of the REST API. This flaw allows unauthenticated users to access sensitive plugin settings, including API keys for integrated services.
Exploitation of this vulnerability leads to unauthorized access to sensitive information, specifically plugin configuration data and API keys.
Users can update to WS Form LITE version 1.10.36 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.