Impact
A missing capability check in the annfu_reset_options() function of the AnnunciFunebri Impresa WordPress plugin allows an authenticated user with Subscriber or higher privileges to delete all 29 plugin options, resetting the plugin to its default state. This loss of configuration can disrupt funeral announcement services and affect the integrity of site data.
Affected Systems
The vulnerability is present in all releases of the AnnunciFunebri plugin up to and including version 4.7.0. WordPress sites that install any of these versions and grant Subscriber or greater roles to users are affected.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS score is below 1%, indicating a low to moderate severity and a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Because exploitation requires a valid WordPress account with Subscriber or higher privileges, the threat primarily comes from compromised or malicious internal accounts rather than external attackers.
OpenCVE Enrichment