Impact
The vulnerability is a missing authorization flaw that allows attackers to bypass the intended access controls of the ApplyOnline plugin for WordPress. Because the plugin does not properly enforce security levels, an attacker can perform actions that should be restricted, potentially gaining unauthorized control over application elements. This weakness is classified as CWE-862, reflecting an absence of proper authentication or authorization checks.
Affected Systems
Affected systems are installations of the Farhan Noor ApplyOnline WordPress plugin with a version of 2.6.7.1 or earlier. The description indicates that all prior releases are impacted, as there is no upper bound version beyond 2.6.7.1. Site owners deploying these plugin versions should treat them as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the medium range, and the EPSS score of less than 1% suggests that active exploitation is currently unlikely. The likely attack vector is remote access to the plugin’s administrative interface via the WordPress site. While the vulnerability does not provide direct remote code execution, it enables unauthorized actions that could compromise confidentiality and integrity of plugin data or the broader WordPress installation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD