Impact
WordPress Maya Business plugin suffers from an Authorization Bypass Through User‑Controlled Key vulnerability that permits users to access functionality that should be limited by ACLs. This IDOR flaw, identified as CWE‑639, enables attackers to reach privileged actions by supplying a crafted key, potentially leading to data leakage or modification of shop settings.
Affected Systems
Vendor paymayapg offers the Maya Business plugin for WordPress. Versions from the initial release through 1.2.0 are affected. The issue remains present in any release that has not applied the fix released after 1.2.0.
Risk and Exploitability
CVSS score of 7.5 indicates a high risk. EPSS is below 1%, suggesting low current exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is likely web‑based; an attacker can manipulate request parameters or URLs to supply a malicious user‑controlled key. No special privileges are required beyond reaching the affected plugin, making it a low‑barrier exploit. Nevertheless, because the flaw allows unauthorized privilege escalation, it should be remediated promptly.
OpenCVE Enrichment
EUVD