Impact
The vulnerability is a missing authorization check in the QuantumCloud SEO Help WordPress plugin. It allows an attacker to bypass configured access control levels and perform privileged actions that should be restricted. This flaw can be leveraged to gain unauthorized access to plugin settings, modify site metadata, or potentially upload arbitrary files if associated actions are available. The weakness corresponds to CWE-862.
Affected Systems
The issue exists in all releases of the QuantumCloud SEO Help plugin from the initial release through version 6.7.9. WordPress sites running any of those versions are at risk. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS v3 score is 6.5 indicating moderate severity. The EPSS score of less than 1% means there is presently a very low probability of exploitation, but the vulnerability is not listed in the CISA KEV catalog. The attack likely requires the attacker to be able to authenticate with the site as a user who has sufficient privileges to interact with the plugin’s interface, or to exploit an unauthenticated access path if any. General exploitation would involve sending crafted requests to the plugin’s endpoints that do not enforce proper role checks.
OpenCVE Enrichment
EUVD