Impact
The vulnerability is a missing authorization flaw that allows an attacker to bypass incorrectly configured access controls in Codexpert, Inc's CoDesigner Woolementor plugin. Because the plugin fails to enforce the defined security levels, users with any level of access could potentially perform restricted actions on the WordPress site, such as modifying content or creating new administrative accounts. The weakness is identified as CWE‑862, which signifies a failure to check user privileges before allowing an operation.
Affected Systems
This issue affects the CoDesigner Woolementor plugin for WordPress versions from the earliest release through version 4.29. All installations of the plugin that have not been updated to at least version 4.30 are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate overall risk. The EPSS score of less than 1% shows that the likelihood of exploitation in the wild is low, and the vulnerability is not currently listed in CISA's KEV catalog. The attack vector is not explicitly stated in the advisory, but based on the nature of the flaw, it is inferred that an attacker would require some form of authenticated access – for example, through an existing user account or administrative interface – to exploit the broken access controls.
OpenCVE Enrichment
EUVD