Impact
Missing Authorization vulnerability in matthewrubin Local Magic allows incorrectly configured access control security levels to be exploited. The flaw enables unauthorized users to bypass plugin restrictions, potentially accessing configuration settings or other protected functionality without proper permissions. This could lead to escalation of privileges within the WordPress site.
Affected Systems
The vulnerability affects the Local Magic plugin by matthewrubin for WordPress up to and including version 2.9.0. Site owners using any of these versions are impacted and need to update to a patched release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1 %, suggesting the likelihood of active exploitation is currently very low. The vulnerability is not listed in CISA KEV. The likely attack vector is through the website’s plugin interface, requiring an authenticated user with configuration rights. Successful exploitation would let the attacker bypass intended access restrictions.
OpenCVE Enrichment
EUVD