Impact
Missing Authorization vulnerability in Nabil Lemsieh HurryTimer allows exploitation of incorrectly configured access control security levels. An attacker can potentially access or manipulate any functionality that is normally restricted to authorized users, such as configuring timers or viewing internal data. The vulnerability does not provide an exploit for arbitrary code execution, but grants unauthorized users the same privileges as legitimate administrators of the plugin.
Affected Systems
WordPress sites running the HurryTimer plugin version 2.13.1 or earlier. The vulnerable product belongs to Nabil Lemsieh and affects all releases from the first available version up to and including 2.13.1.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS < 1% shows a very low predicted exploitation probability. The vulnerability is not listed in CISA KEV. Likely exploitation occurs via HTTP requests made to the plugin’s administrative endpoints, possibly without needing authentication if the access control checks are missing. An attacker with network visibility to the site could send crafted requests to gain unauthorized access to plugin configuration and data.
OpenCVE Enrichment
EUVD