Impact
The 1003 Mortgage Application plugin for WordPress contains a missing authorization flaw that allows attackers to bypass configured access control levels. By sending specially crafted requests to privileged endpoints, an unauthenticated actor can gain access to restricted functionality or data. This is a typical broken access control vulnerability, identified as CWE-862.
Affected Systems
All releases of the 1003 Mortgage Application plugin from the initial version through version 1.87 are affected. The product is distributed by 8blocks and deployed on WordPress sites that install the plugin.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no confirmed active exploitation has been reported. Likely attack vectors involve remote web interactions with the plugin’s administrative interfaces, requiring no special privileges beyond the ability to craft HTTP requests.
OpenCVE Enrichment
EUVD