Impact
The vulnerability is a missing authorization flaw that lets a user bypass incorrectly configured access controls and potentially use the Hide WP Toolbar plugin with elevated privileges. It is classified as CWE-862, indicating that the plugin failed to enforce proper role checks before allowing access.
Affected Systems
The issue affects the WordPress Hide WP Toolbar plugin developed by Jeremy Saxey, versions from the earliest releases through 2.7 and earlier. Any WordPress installation that has this plugin installed and has not applied an update beyond 2.7 is potentially affected.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires access to a user account that can interact with the plugin, and the improper access control allows that account to perform actions normally restricted to administrators. The risk remains if the website permits any authenticated user to load the plugin interface or if the plugin is exposed via public URLs.
OpenCVE Enrichment
EUVD