Impact
The vulnerability is a missing authorization flaw (CWE‑862) that permits attackers to execute actions normally reserved for privileged users. When the WooMS plugin is configured with incorrect access control settings, an unauthenticated or low‑privileged user can invoke functions that lack proper role checks.
Affected Systems
Affected systems are WordPress sites that have installed the WooMS plugin from wpcraft, with any version up to and including 9.12. The flaw resides in public plugin endpoints that do not enforce the expected role restrictions.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of <1 % suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to access the plugin’s web interface and trigger the vulnerable endpoint; the lack of an injection vector limits the attack surface, but a misconfigured access control could lead to unauthorized data exposure or function execution.
OpenCVE Enrichment
EUVD