Impact
Elliot Sowersby / RelyWP Coupon Affiliates contains a Missing Authorization flaw that permits attackers to alter crucial configuration options. The vulnerability arises from incorrectly defined access control levels, which can allow a user with inadequate privileges to modify settings. Such changes can compromise the intended functionality of the plugin or weaken security controls, thereby affecting the confidentiality and integrity of website operations.
Affected Systems
The Elliot Sowersby / RelyWP Coupon Affiliates plugin version 6.4.0 and earlier are affected. Systems running these outdated releases on WordPress sites should be considered vulnerable. No specific implementations beyond the standard licensed plugin are indicated.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Nonetheless, attackers could exploit this flaw by leveraging a WordPress account with insufficient privileges; the required attack vector is inferred to be authenticated within the WordPress administrative interface.
OpenCVE Enrichment
EUVD