Impact
The vulnerability is a missing authorization flaw that allows unauthenticated or improperly authenticated users to access functionalities that should be restricted, such as message handling or other privileged actions within the Raychat plugin. This can lead to unauthorized data disclosure, manipulation of chat content, and potential defacement or abuse of the application. The flaw is categorized as CWE-862, indicating an absence of proper access control checks.
Affected Systems
WordPress installations running the Raychat plugin, any version 2.1.0 or earlier. The issue applies to all versions identified from the plugin’s earliest available release through version 2.1.0.
Risk and Exploitability
The CVSS base score of 5.3 reflects a moderate impact level. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is very low. The vulnerability is not listed in the CISA KEV catalog, further indicating limited known exploitation. Attackers would likely send crafted HTTP requests to the plugin’s exposed endpoints to bypass authorization checks, although the exact prerequisites for a successful exploit are not detailed in the advisory.
OpenCVE Enrichment
EUVD