Impact
The Nuanced Media WP Meetup plugin for WordPress contains a Missing Authorization flaw (CWE‑862) that allows an attacker to alter its settings without proper privileges. By modifying event listings, visibility controls, or security features, an unauthorized user can disrupt site operations or facilitate further exploitation. Although the vulnerability does not directly enable remote code execution, the ability to reconfigure the plugin undermines the integrity and availability of the WordPress site.
Affected Systems
This issue affects Nuanced Media WP Meetup plugin versions up to and including 2.3.0, which are installed on WordPress sites. Users of these or earlier releases are vulnerable to unauthorized changes of the plugin’s configuration.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity, and the EPSS score is reported as less than 1 %, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most plausible attack vector involves submitting requests to the plugin’s settings interface via the web front‑end or admin pages; if an attacker can reach these endpoints, they can change configuration without authentication. No public exploits are documented, but the low EPSS suggests limited current prevalence.
OpenCVE Enrichment
EUVD