Impact
The vulnerability is an incorrect privilege assignment flaw in the One-Login plugin for WordPress, allowing entities that should not have elevated rights to gain higher privileges. This flaw leads to privilege escalation, enabling attackers to take control or access sensitive data that would normally be protected. The weakness corresponds to CWE-266, which involves mismanagement of access control.
Affected Systems
The issue affects the WordPress One-Login plugin released by ifkooo, specifically versions from the earliest release up to and including 1.4. Users running any of these plugin versions are susceptible to the escalation attack. The vulnerability is not tied to a particular operating system or WordPress core version, but is limited to the plugin itself.
Risk and Exploitability
With a CVSS score of 8.1, the exploitation risk is considered high. The EPSS score is below 1 %, indicating a very low probability of widespread exploitation in the near term, and it is not listed in CISA’s KEV catalog. The most likely attack vector is a remote attacker submitting crafted requests that manipulate the plugin’s permission logic, potentially after authenticating with a low‑privilege user account or exploiting a default configuration.
OpenCVE Enrichment
EUVD