Impact
Based on the description, a broken access control vulnerability in Soft8Soft LLC Verge3D allows attackers to exploit incorrectly configured security levels, enabling unauthorized access to plugin functionality. The flaw can expose sensitive data or perform privileged actions after bypassing role checks. The weakness falls under CWE-862 and has been cataloged as a moderate severity issue.
Affected Systems
The affected product is the WordPress Verge3D plugin developed by Soft8Soft LLC, with vulnerable versions from installation through 4.9.4. Any WordPress site using this plugin and running an affected version is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium overall impact, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. Based on the description, the likely attack vector is through web requests to endpoints that lack proper permission checks, leveraging remote access. The plugin is not listed in CISA's KEV catalog. Due to the lack of an active exploit track, immediate risk remains moderate, but sites should secure or upgrade the plugin promptly.
OpenCVE Enrichment
EUVD