Impact
The Hive Support plugin suffers from a missing authorization flaw that allows attackers to gain unauthorized access to administrative functions. Because the plugin’s access control levels are incorrectly configured, any authenticated user—or potentially unauthenticated user if the plugin exposes open endpoints—can perform privileged actions such as viewing or modifying support data. The weakness corresponds to the CWE-862 category, indicating an insecure direct object reference that lets users access resources they should not.
Affected Systems
The vulnerability is present in WordPress installations that use the Hive Support plugin up through version 1.1.6. The affected product is the Hive Support plugin from the vendor Hive Support.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk. The EPSS score of <1% means that real‑world exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is probably via a logged‑in user who can exploit the broken access controls; an attacker with any low‑privileged role on the site could potentially elevate their capabilities or read restricted data. No public exploit has been disclosed, and remediation is through patching or configuration.
OpenCVE Enrichment
EUVD