Description
Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RepairBuddy: from n/a through <= 3.8213.
Published: 2025-04-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the RepairBuddy plugin allows attackers to exploit incorrectly configured access control settings, enabling actions on the WordPress site that should be prohibited. This flaw can let unauthorized users view or modify repair shop information, client data, or other protected resources. The weakness is a classic broken access control (CWE-862) situation where permissions are not properly enforced. Based on the description, it is inferred that the vulnerability arises from incorrectly configured user permissions within the plugin’s settings and that an attacker may need to be authenticated as a user with plugin access.

Affected Systems

The affected product is the RepairBuddy computer-repair-shop plugin created by Ateeq Rafeeq. Versions from the earliest release up through 3.8213 are vulnerable. Any WordPress installation running any of those versions carries the risk.

Risk and Exploitability

The CVSS base score is 4.3, indicating a moderate impact when used in combination with other flaws. The EPSS score is less than 1%, suggesting that exploitation is unlikely but not impossible. The vulnerability is not listed in CISA's KEV catalog, but administrators should still evaluate the risk based on the plugin’s role and the data it handles. Based on the description, it is inferred that exploitation requires only that an attacker achieves interaction with the plugin’s management interface, and no special network privileges are needed beyond normal access to the site.

Generated by OpenCVE AI on May 1, 2026 at 11:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RepairBuddy to a version newer than 3.8213 or apply the vendor‑provided patch once available.
  • If an upgrade is not immediately possible, review the permissions granted to users who can access the plugin’s interface and ensure only trusted administrators have those rights.
  • As a temporary measure, remove or disable the RepairBuddy plugin from the WordPress installation until a patched version is released.

Generated by OpenCVE AI on May 1, 2026 at 11:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9772 Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211. Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RepairBuddy: from n/a through <= 3.8213.
Title WordPress RepairBuddy plugin <= 3.8211 - Broken Access Control vulnerability WordPress RepairBuddy plugin <= 3.8213 - Broken Access Control vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 08 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.
Title WordPress RepairBuddy plugin <= 3.8211 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:20.603Z

Reserved: 2025-04-04T10:02:30.560Z

Link: CVE-2025-32277

cve-icon Vulnrichment

Updated: 2025-04-08T18:59:07.329Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:39.170

Modified: 2026-04-23T15:28:53.230

Link: CVE-2025-32277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:15:15Z

Weaknesses