Impact
The vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control settings in the People Lists plugin. Because the plugin fails to enforce proper permission checks, users who should not have access can read or modify restricted user information, leading to potential data disclosure or tampering. This demonstrates a classic access control weakness (CWE‑862).
Affected Systems
The affected product is the People Lists plugin (ctltwp:People Lists) for WordPress. Versions from the earliest release through 1.3.10 are impacted. Versions 1.3.11 and later contain the fix.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% reflects a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need a web-based access vector and could exploit the flaw by accessing the plugin's interfaces with insufficient privilege checks, potentially after creating or using a legitimate user account. Given the low EPSS and moderate CVSS, the overall risk is moderate but warrants timely remediation.
OpenCVE Enrichment
EUVD