Impact
A missing authorization flaw in the QuanticaLabs CSS3 Compare Pricing Tables for WordPress plugin allows an attacker to bypass intended access controls and reach functions or data that should be restricted. This type of weakness can expose sensitive pricing information or enable manipulation of the plugin’s settings, compromising the integrity and confidentiality of the site’s content. The vulnerability is described by CWE‑862 and is identified as a missing authorization error.
Affected Systems
The flaw impacts QuanticaLabs CSS3 Compare Pricing Tables for WordPress plugin versions 11.6 and all earlier releases. Any WordPress site that has installed this plugin without applying a newer version that removes the flaw is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% suggests that exploitation is unlikely under current conditions. The vulnerability is not listed in the CISA KEV catalog. Likely the attack vector involves unauthenticated or low‑privilege web requests that interact with the plugin’s restricted endpoints; the description infers that incorrectly configured access levels can be exploited, though explicit exploitation steps are not detailed.
OpenCVE Enrichment
EUVD