Sceawere

Vulnerability Detail

CVE-2026-32472UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Broken Access Control in Online Contact Widget

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
wbolt.com
Product
Online Contact Widget
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T15:16:52.817Z",
  "pubdate": "2026-08-18T15:16:52.817Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability has been identified in the Online Contact Widget plugin affecting versions 1.3.0 and prior. This security flaw arises from a failure to properly validate user sessions, permissions, or access control checks within sensitive endpoints or functionalities exposed by the widget.\nThe vulnerability allows remote, unauthenticated attackers to interact with restricted functions or access sensitive data normally protected against unauthorized access. Successful exploitation of this flaw can lead to unauthorized data disclosure, administrative function manipulation, or unintended interactions depending on the specific backend logic exposed by the vulnerable component.\nThe risk implications are significant due to the lack of authentication requirements, enabling threat actors to automate exploitation attempts over the network with minimal friction. Remediation requires updating the Online Contact Widget to a patched version once available or applying strict access control enforcement mechanisms to the affected endpoints.",
  "technicalDetails": "The root cause of this vulnerability is improper authorization handling within the Online Contact Widget <= 1.3.0. The application fails to implement robust access control checks to verify whether incoming HTTP requests originate from authenticated or authorized users before executing sensitive operations or returning restricted data.\nThe vulnerable component resides within the codebase of the Online Contact Widget, specifically handling request routing and endpoint execution without enforcing privilege validation layers. Because the vulnerability is unauthenticated, attackers do not require valid credentials, session tokens, or specific privilege levels to interact with the vulnerable code paths.\nNetwork exposure is external, meaning any remote attacker with network connectivity to the targeted web application can initiate requests directly to the exposed endpoints. The attack flow typically begins with an attacker identifying the exposed functionality via URL enumeration or component fingerprinting.\nOnce the target endpoint is identified, the attacker crafts a malicious HTTP request targeting the function without providing authentication headers or valid session cookies. Due to the lack of access control enforcement, the backend application processes the request, bypasses security boundaries, and executes the underlying functionality.\nDepending on the exact implementation of the vulnerable handler, payload behavior may involve unauthorized retrieval of sensitive contact data, submission manipulation, or execution of privileged routines. Post-exploitation impact encompasses potential data exfiltration, unauthorized modification of application state, or further compromise of the underlying web application environment through leveraged functionality."
}
CVE-2026-32472: Unauthenticated Broken Access Control in Online Contact Widget (HIGH Severity, CVSS: 7.5) - Sceawere