Impact
The Supervisor plugin for WordPress contains missing capability checks on several AJAX functions in all versions up to and including 1.3.2. This flaw permits an authenticated user with Subscriber-level access or higher to alter plugin configuration settings. While it does not provide remote code execution or privilege escalation to super admin, the ability to modify the settings can influence the plugin’s behavior, potentially enabling malicious features or disabling security controls, which may degrade the site’s integrity or availability.
Affected Systems
Vendor: tiagohillebrandt; Product: Supervisor plugin for WordPress; Versions affected: all releases up to and including 1.3.2. Users of any WordPress site that have installed these versions are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is listed as not part of the CISA KEV catalog. The attack requires an authenticated user with at least Subscriber role; it is most likely to be abused in a scenario where an attacker has accessed a legitimate account. After authenticating, the attacker can send crafted AJAX requests to modify settings, achieving unwarranted changes that could affect site functionality.
OpenCVE Enrichment