Impact
The Moosend Landing Pages plugin for WordPress lacks a capability check on the function that handles subscriber interactions, allowing any authenticated user with Subscriber-level access or higher to delete the 'moosend_landing_api_key' option. This flaw is a missing authorization weakness (CWE‑862) and can lead to loss of service or disruption of the plugin’s integration with Moosend. The impact is limited to modification of a plugin setting, but it can compromise the functionality of marketing forms that rely on that key.
Affected Systems
The vulnerability affects the Moosend Landing Pages plugin for WordPress, all releases up to and including version 1.1.6. Users who have installed any of these versions and have at least Subscriber-level account permissions are at risk.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is of moderate severity. The EPSS score is below 1% and the flaw is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. The attack vector involves authenticated access; an attacker who gains or already possesses a Subscriber account can trigger the deletion simply by visiting the endpoint that executes the unauthorized function. No additional system compromise or network-level attack is required.
OpenCVE Enrichment