Impact
The vulnerability is an incorrect privilege assignment flaw in the miniOrange Custom API for WP plugin, classified as CWE‑266. It allows an attacker to elevate their privileges and gain high‑level access to the WordPress site, potentially leading to data theft, modification, or arbitrary code execution.
Affected Systems
Any installation of the miniOrange Custom API for WP plugin with a version of 4.2.2 or earlier is affected. This includes all releases ranging from the first available version through to 4.2.2.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity, and although the EPSS score is less than 1 %, suggesting a low likelihood of exploitation at this time, the potential impact remains high. The vulnerability is not listed in the CISA KEV catalog, but the absence of active exploitation reports does not diminish the risk. The likely attack vector is remote via the plugin’s exposed API endpoints and requires manipulation of the privilege assignment logic, which may be achievable by an authenticated user with limited rights. Once exploited, the attacker would have unrestricted administrative access to the WordPress backend.
OpenCVE Enrichment
EUVD