Impact
The Kadence WooCommerce Email Designer plugin contains an incorrect privilege assignment flaw that enables attackers to elevate their privileges within a WordPress installation. By exploiting the flaw, a user with limited access—such as any authenticated WordPress account with standard capabilities—can transform into an administrator, gaining full control over the site. The primary consequence is a compromise of confidentiality, integrity, and availability of the entire CMS.
Affected Systems
StellarWP’s Kadence WooCommerce Email Designer plugin, any version up to and including 1.5.16, bears the vulnerability. Users running older versions without the forthcoming patch are at risk.
Risk and Exploitability
The CVSS base score of 7.2 indicates a high severity level. The EPSS score of less than 1% shows a low probability that the flaw is currently being exploited in the wild, and it is not present in the CISA KEV catalog. The likely attack vector is an authenticated use of the WordPress site; an attacker doesn’t need external access, only a legitimate but low‑privileged user account. This opportunity points to a local privilege escalation scenario.
OpenCVE Enrichment
EUVD