Impact
The flaw is an incorrect privilege assignment in the pebas CouponXxL Custom Post Types plugin that allows a user with lower permissions to elevate their level of access. This vulnerability can enable an attacker to modify content, change configuration settings, or gain other administrative capabilities beyond what their role originally permits. The weakness corresponds to CWE‑266, improper authorization controls.
Affected Systems
All releases of the CouponXxL Custom Post Types plugin from pebas up to and including version 3.0 are vulnerable. No later versions are listed as affected in the CVE data.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity issue, while the EPSS score of less than 1 % suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack path is through the WordPress dashboard or the plugin’s interface, where a user with limited rights could exploit the flawed role assignment to gain elevated privileges.
OpenCVE Enrichment
EUVD