Impact
An access control flaw in the Ronik@UnlimitedWP Project Cost Calculator plugin allows attackers to exploit incorrectly configured security levels, potentially gaining unauthorized access to privileged functions within the plugin. This could lead to manipulation or exposure of project cost data, or even the execution of actions normally reserved for administrators.
Affected Systems
vulnerability affects all WordPress installations running the Project Cost Calculator plugin versions from the initial release through version 1.0.0 inclusive.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium to high risk profile. The EPSS score of < 1% suggests a very low probability of active exploitation at present. The vulnerability is not listed in CISA KEV, implying no known large-scale exploitation. Attackers would target the plugin’s web interface, leveraging the missing authorization checks to elevate privilege or access restricted data.
OpenCVE Enrichment
EUVD