Impact
Based on the description, it is inferred that a missing authorization flaw allows attackers to bypass role‑based restrictions within the QS Dark Mode plugin. This vulnerability can enable an attacker to alter plugin settings or invoke administrative functions that should be limited to privileged users, potentially compromising the integrity of the WordPress site.
Affected Systems
The bug affects all versions of Quomodosoft QS Dark Mode for WordPress up through 3.0. Any WordPress installation that has this plugin installed and is running a legacy version is vulnerable.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user with a standard role interacting with the plugin’s administrative interface, or an unauthenticated user if the plugin exposes public endpoints. This inference follows from the description of the broken access control.
OpenCVE Enrichment
EUVD