Impact
The vulnerability is a missing authorization check that allows a user with inadequate permissions to bypass access controls within the UpStream Project Management plugin. As a result, an attacker could potentially view, modify, or delete project information, compromising data confidentiality and integrity. The weakness is identified as CWE‑862 – Missing Authorization.
Affected Systems
The affected system is the UpStream Project Management plugin for WordPress, versions up to and including 2.1.1. No other vendors or products are affected according to the CNA data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation. The vulnerability is not listed in CISA keV. The likely attack vector is a web‑based request to the plugin’s endpoints that rely on incorrect security level configuration; based on the description, it is inferred that an attacker would need to identify a target site running the vulnerable plugin and craft a request to exploit the access control flaw.
OpenCVE Enrichment
EUVD