Impact
Missing Authorization vulnerability in the softnwords SMM API plugin allows an attacker to bypass configured access control levels, enabling unauthorized viewing or modification of protected content. This flaw is a classic example of CWE‑862, where insufficient checks for user privileges result in elevation or lateral movement within the WordPress environment.
Affected Systems
The affected product is the WordPress plugin SMM API from softnwords, versions up through 6.0.31 inclusive. Any installation using these or earlier releases is potentially vulnerable; the vulnerability description specifies that the issue spans from n/a through the 6.0.31 release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the vulnerability is not listed in CISA KEV, implying no known public exploits at this time. Based on the description, it is inferred that the attack vector is web‑based, involving interaction with the plugin’s API endpoints or administrative interfaces without proper authorization checks.
OpenCVE Enrichment
EUVD