Impact
The Site Offline plugin contains an incorrect privilege assignment flaw that allows users with lower permissions to perform actions that should be restricted to administrators. This broken access control can enable an attacker to read sensitive site information, modify site settings, or potentially insert malicious content, directly compromising the confidentiality and integrity of the website. The weakness is a classic example of CWE-266: Insecure Permissions.
Affected Systems
WordPress plugin Site Offline, vendor chandrashekharsahu, affected versions are all releases up to and including 1.5.7. Current releases beyond 1.5.7 are presumed to contain the fix, but no version threshold is documented beyond this range.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests that exploit attempts are unlikely at this time. The vulnerability is not listed in the CISA KEV catalog, reducing immediate concern. Attackers would need to interact with the website's front‑end or back‑end interfaces, making remote exploitation possible through normal web requests. Because the issue stems from misconfigured access controls, it does not require privileged physical access or a zero‑day exploit.
OpenCVE Enrichment
EUVD