Impact
The vulnerability is a missing authorization flaw in the KI Live Video Conferences plugin for WordPress. It permits actors who can reach the plugin’s endpoints to access functions that should be restricted to privileged users. The result is an unauthorized access bypass that can expose or alter conference management features, affecting confidentiality and integrity of meeting data. This is classified as a CWE-862: Lack of Access Control.
Affected Systems
The flaw affects the KI Live Video Conferences plugin by whassan, versions from the first release through 5.5.15. WordPress sites running any of these versions of the plugin are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web interface of a WordPress site, where an attacker could craft requests to the plugin’s endpoints to bypass access checks. Attack prerequisites include network access to the WordPress site and an authenticated user session that the plugin incorrectly treats as privileged. No privilege escalation beyond the web application context is described in the public data.
OpenCVE Enrichment
EUVD