Impact
The Cloak Front End Email plugin for WordPress contains a missing authorization flaw that permits users without proper permissions to modify email configuration settings. This broken access control (CWE‑862) can allow an attacker to alter how emails are handled by the plugin. The flaw originates from incorrectly configured access control security levels, enabling unauthorized changes to configuration.
Affected Systems
Any WordPress site running the webbernaut Cloak Front End Email plugin, version 1.9.5 or older, is affected. The plugin’s documented vulnerable range extends from the earliest version (n/a) through 1.9.5.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as High. EPSS indicates an exploitation probability of less than one percent, suggesting that the exploit is currently rare but not impossible. Although the CVE description does not specify how the exploit is carried out, it is inferred that a user with administrative privileges to the WordPress site who can access the plugin configuration might use the missing check to modify settings. The CVE is not listed in CISA’s KEV catalog, reducing concerns about a widely published exploit.
OpenCVE Enrichment
EUVD