Impact
This vulnerability is a missing authorization flaw in the looks_awesome Team Builder WordPress plugin. The plugin’s access control settings are incorrectly configured, permitting users who should not have privileged access to perform actions beyond the intended scope. This flaw is identified as CWE‑862 and could lead to unauthorized disclosure or alteration of information.
Affected Systems
Any installation of the Team Builder plugin created by looks_awesome on WordPress sites that runs version 1.5.7 or earlier is affected. The issue is present in all releases from the initial version up to and including 1.5.7.
Risk and Exploitability
The CVSS score of 7.6 classifies this vulnerability as high severity. EPSS indicates a low current exploitation probability (<1%). The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit the vulnerability via the web interface of the site, accessing plugin pages or API endpoints without proper authorization. While no public exploits are documented, the ability to elevate privileges or read sensitive data poses a significant risk if the plugin is used to store confidential information.
OpenCVE Enrichment
EUVD