Impact
WordPress DefendWP Firewall plugin contains a missing authorization vulnerability, allowing attackers to exploit incorrectly configured access control security levels. This flaw enables unauthorized users to bypass the plugin’s intended restrictions, potentially accessing or altering protected configuration settings.
Affected Systems
The vulnerability affects the DefendWP Firewall plugin from the earliest available versions through 1.1.0, as maintained by revmakx. Any WordPress site that has installed the plugin up to version 1.1.0 is at risk.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high severity, though the EPSS score of less than 1% suggests a low probability of exploitation at this time and the flaw is not listed in CISA's KEV catalog. Attacks could be launched remotely via the web interface, and may require only authentication as a regular user or even unauthenticated access if the plugin’s security settings are misconfigured.
OpenCVE Enrichment
EUVD