Impact
The vulnerability is a missing authorization flaw allowing attackers to exploit incorrectly configured access limits in the A WP Life Login Page Customizer plugin. If triggered, an attacker could view, edit or delete restricted administrative content, effectively bypassing role‑based access controls. This breach of confidentiality and integrity could lead to service disruption or compromise of website data.
Affected Systems
WordPress sites running the A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Design plugin version 2.1.1 or older are affected. The issue applies from the earliest release to version 2.1.1 inclusive.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The plugin is not listed in CISA’s KEV catalog. The lack of detailed attack vector information in the description means the likely path involves an authenticated user or a user who can guess the admin URL, assuming the plugin exposes administrative functions without proper checks. Consequently, the risk to an organization depends on its exposure to the internet, the presence of the vulnerable plugin version, and the effectiveness of its overall access controls.
OpenCVE Enrichment