Impact
The vulnerability is a missing authorization flaw in Agulatechnologies WP Customer Area that results from incorrect enforcement of security levels on protected content. According to the description, the flaw permits exploitation of incorrectly configured access control, which aligns with CWE‑862 and can lead to unintended disclosure of private data. The impact is a breach of confidentiality resulting from the system allowing users to view content they should not be able to see.
Affected Systems
WordPress sites that have installed version 8.3.4 or earlier of the WP Customer Area plugin are affected. All installations of the plugin from the earliest release through 8.3.4 should be evaluated and updated if applicable.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the low to moderate risk range, while an EPSS score of less than 1% indicates a very low likelihood of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred to be a web request that targets the plugin’s protected endpoints, as the lack of proper authorization is described in the context of web‑layer access control layers.
OpenCVE Enrichment
EUVD