Impact
The vulnerability is a missing authorization flaw that allows attackers to access functionality not properly protected by access control lists. Because the plugin fails to verify user permissions before performing certain actions, an attacker could manipulate or view data that should be restricted.
Affected Systems
Realty Workstation plugin for WordPress, versions up through 1.0.45, is affected. Any WordPress site using this plugin version is at risk.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. The EPSS score of less than 1% suggests exploitation is currently unlikely but it remains possible. The vulnerability is not listed in CISA KEV. Attackers can likely exploit this flaw via web requests to the plugin’s unauthenticated endpoints; the precise vector is inferred from the description as the exploit requires only that the endpoint be reached without correct ACL checks.
OpenCVE Enrichment
EUVD