Impact
The WP ERP plugin contains a missing authorization flaw that permits an attacker to bypass configured security levels. The weakness, classified as CWE‑862, enables unauthorized users to read, modify, or delete data that should be protected by the plugin’s role checks, potentially compromising confidentiality and integrity of the ERP data.
Affected Systems
The vulnerability affects the weDevs WP ERP plugin for WordPress for all versions from the first release through 1.13.4. Any WordPress site that has the plugin installed at or below version 1.13.4 is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity; the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The flaw is not listed in the CISA KEV catalog. A correct inference is that exploitation requires exploiting the plugin’s administrative interfaces, implying the attacker must be authenticated or have some access to the site’s backend. Once access is gained, the lack of proper role checks allows privilege escalation within the ERP module, enabling entitlement abuse.
OpenCVE Enrichment
EUVD