Impact
The vulnerability is an Authorization Bypass Through User‑Controlled Key flaw in the Nirweb support plugin (CWE‑639). It allows an attacker to manipulate user‑controlled keys to bypass normal authorization checks within the plugin, potentially granting unauthorized actions.
Affected Systems
This flaw affects the WordPress plugin Nirweb support from the NirWp Team, with all released versions up to and including 3.0.3. The plugin is deployed on WordPress sites where administrators or other users may have access to its configuration and key‑management functionality.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate impact. The EPSS score is below 1%, suggesting that the exploit probability is low. The vulnerability is not listed in the CISA KEV catalog. Because the plugin runs within a WordPress environment and the flaw involves user‑controlled parameters, the likely attack vector is a web‑based request that substitutes or manipulates key values during plugin interaction. There are no known public exploits or workarounds listed.
OpenCVE Enrichment
EUVD