Impact
The vulnerability is a missing authorization flaw that enables an attacker to bypass the plugin’s access‑control checks. With incorrectly configured security levels, the attacker can perform actions reserved for privileged users, such as viewing or editing business directory entries. This flaw can lead to unauthorized disclosure of private listing information, alteration of entries, or overall tampering with the directory data, thereby compromising both confidentiality and integrity.
Affected Systems
The flaw affects the Chamber Dashboard Business Directory plugin, developed by Chandrika Guntur, Morgan Kay. All releases from the earliest version up to and including 3.3.8 are vulnerable. Any WordPress site that has installed the plugin within this version range is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in CISA KEV, so no large‑scale attacks have been reported. The attacker would need to reach an administrative interface or other exposed endpoint of the WordPress site. Based on the description, the likely attack vector is exploitation of the plugin’s admin URLs, which could be accessed by unauthenticated or low‑privilege users if the site’s access controls are weak.
OpenCVE Enrichment
EUVD