Impact
The vulnerability originates from missing authorization checks in the LifePress plugin, allowing an attacker to perform actions typically restricted to privileged users. This broken access control results in the potential for unauthorized data modification, disclosure, or tampering with the WordPress site, thereby compromising both integrity and confidentiality of content managed by the plugin. The weakness is classified as CWE-862, a classic missing privilege enforcement flaw.
Affected Systems
The affected product is the WordPress LifePress plugin developed by Ashan Perera, versions from the initial release up to and including 2.1.3. Users of this plugin on any WordPress installation are at risk when the plugin remains at or below this version threshold.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score of less than 1% reflects a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Likely exploitation occurs via the web interface when authenticated as a regular user, bypassing controls that should limit certain functionalities to administrators. An attacker can leverage this to gain unauthorized access to sensitive plugin data or trigger unintended behaviors.
OpenCVE Enrichment
EUVD