Impact
The CubeWP Framework Plugin contains a flaw in privilege assignment that permits an attacker to elevate their rights within a WordPress site. By exploiting this weakness, an attacker can gain administrative or higher-level access, potentially taking full control over site settings, content, and user accounts. The vulnerability is classified as CWE‑266, reflecting improper privilege management.
Affected Systems
The vulnerability affects the Imran Tauqeer CubeWP Framework Plugin for all versions from the initial release through version 1.1.24 inclusive.
Risk and Exploitability
This issue carries a CVSS score of 8.8, indicating a high severity. The EPSS indicates a very low probability of exploitation (<1%). The vulnerability is not currently listed in CISA’s KEV catalog. While the high severity score hints at a significant potential impact, the low exploitation likelihood and the need for some form of initial access to the site diminish the immediate threat level. Nonetheless, administrators should treat it as a serious concern due to the possibility of full administrative takeover once compromised.
OpenCVE Enrichment
EUVD