Impact
A missing authorization flaw in the Quý Lê 91 Administrator Z plugin allows a user to gain higher privileges than intended. The vulnerability is captured by CWE‑862 (Missing Authorization) and the description limits the impact to the elevation of privileges within the WordPress site, with no additional consequences such as content tampering mentioned.
Affected Systems
All releases of the Quý Lê 91 Administrator Z plugin up to and including version 2025.03.24 are affected. WordPress sites that have installed any of these plugin versions expose administrators and other users to this privilege escalation risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, while the EPSS score of <1% shows a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves interaction with the plugin’s administrative interfaces or API endpoints, which an attacker can reach if the WordPress site is publicly accessible or if the attacker already possesses some level of authenticated access.
OpenCVE Enrichment
EUVD