Impact
This vulnerability is an incorrect privilege assignment flaw in the Simple Business Directory Pro plugin provided by quantumcloud. Affected installations allow an attacker to increase their privileges within the WordPress site, potentially gaining administrative control. The weakness is classified as CWE-266.
Affected Systems
WordPress sites running the quantumcloud Simple Business Directory Pro plugin on any version prior to 15.6.9 are affected. Users running version 15.6.8 or older are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, but the EPSS of < 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation. The likely attack vector requires an authenticated user with some level of access to the plugin settings; detailed prerequisites are not disclosed in the description. The risk remains high due to the potential for attackers to reach full site control if the flaw is exploited.
OpenCVE Enrichment
EUVD