Impact
The vulnerability resides in the WP Helper Premium plugin version 4.6.1 or earlier. A missing authorization check in the plugin allows an attacker to invoke functions that should be restricted to privileged users, enabling access to administrative features, content modification, configuration changes, or user data manipulation without proper authentication.
Affected Systems
Mat Bao Corporation WP Helper Premium plugin installed on WordPress sites, from any version through 4.6.1. Site owners running the plugin before the 4.6.2 release are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS <1% suggests a low likelihood of exploitation at the moment. This flaw is not listed in the CISA KEV catalog. The likely attack vector is a web request to the plugin’s endpoints, where an exploit can bypass access controls and allow an adversary—potentially an authenticated user or even an unauthenticated attacker capable of crafting requests—to perform actions normally reserved for administrators, potentially leading to data tampering, content injection, or configuration changes.
OpenCVE Enrichment
EUVD