Impact
Missing authorization in the REHub Framework plugin allows attackers to reach features that should be limited to privileged users. The flaw can result in unauthorized data exposure or manipulation of the plugin’s administrative functions, representing a clear privilege escalation path. The weakness is formally identified as CWE‑862.
Affected Systems
The vulnerability affects WordPress installations that use the sizam REHub Framework plugin version 19.9.5 or earlier. Any site running this plugin before 19.9.6 is potentially exposed.
Risk and Exploitability
The CVSS score of 7.5 reflects moderate to high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Based on the nature of the defect, the likely attack vector would involve sending requests to the plugin’s restricted endpoints, either through the WordPress administrative interface or exposed REST routes, and exploiting the absent permission checks. The details of the request pathway are not explicitly outlined in the description but are inferred from the missing authorization context.
OpenCVE Enrichment