Impact
An incorrect privilege assignment flaw in the Progress Planner WordPress plugin allows an attacker to elevate privileges. The vulnerability can let a user gain full administrator rights, potentially compromising site data, configurations, and content. The weakness is a classic CWE-266 scenario of improper privilege assignment.
Affected Systems
The Progress Planner plugin for WordPress, version 1.8.0 and earlier, is affected. All installations using these releases are at risk.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity issue, while an EPSS of less than 1% indicates a low likelihood of exploitation at present. It is not yet listed in CISA’s KEV catalog. Though the description does not state the precise attack vector, it can be inferred that an authenticated user with sufficient access to the plugin’s settings can trigger the privilege escalation. No publicly disclosed workaround is available.
OpenCVE Enrichment