Impact
The CVE identifies an incorrect privilege assignment flaw in the John James Jacoby WP User Profiles plugin, which allows a lower‑privileged user to gain higher permissions within a WordPress site.
Affected Systems
The WP User Profiles plugin by John James Jacoby, version 2.6.2 and earlier, is vulnerable. All releases that precede and include 2.6.2 are affected.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, while an EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability does not appear in the CISA KEV catalog. Based on the description, it is inferred that exploiting the flaw would involve leveraging an authenticated session to manipulate the plugin’s role‑assignment logic, but the exact attack vector is not specified in the CVE details.
OpenCVE Enrichment
EUVD