Impact
Missing authorization checks allow a user with delete permissions to remove any content type that the plugin manages. This flaw can result in the loss of posts, pages, media, or other data, leading to data integrity violations and potential service disruption.
Affected Systems
The vulnerability affects the WordPress plugin SUMO Memberships for WooCommerce from any version earlier than 7.8.0, developed by FantasticPlugins.
Risk and Exploitability
With a CVSS score of 6.5, the flaw presents moderate risk. The EPSS score is below 1%, indicating low public exploitation probability at present, and it is not listed in the CISA KEV catalog. The likely attack surface involves a compromised or overly privileged account; an attacker could delete arbitrary content by navigating the plugin’s delete functions, which are insufficiently protected.
OpenCVE Enrichment