Impact
Rootspersona plugin for WordPress has a missing authorization vulnerability that allows attackers to bypass the plugin’s access control settings. The flaw is present in all versions up to and including 3.7.5. By exploiting this issue, an unauthenticated or minimally privileged user could access restricted functions or data, potentially reading, modifying, or deleting content or configuration settings and thereby compromising the confidentiality, integrity, or availability of the site.
Affected Systems
Any WordPress installation that has the ed4becky Rootspersona plugin version 3.7.5 or earlier is impacted. The vulnerability applies across the full range of affected releases; users should verify their plugin version and update if it falls within the vulnerable scope.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk, while the EPSS score of less than 1% suggests that the likelihood of exploitation remains low. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to target a site with the plugin installed and locate an exposed endpoint or administrative URL that is missing proper authorization checks, then submit crafted requests to perform unauthorized actions.
OpenCVE Enrichment
EUVD