Impact
The Profiler – What Slowing Down Your WP plugin contains a missing authorization check in the wpsd_plugin_control() function in all releases up to and including 1.0.0. Because of this, anyone able to reach the Profiler page can reactivate plugins that have been previously disabled without needing to be logged in. This unexpected ability to alter the active plugin set exposes the site to potential integrity or availability problems, especially if a reactivated plugin has its own vulnerabilities or exploits.
Affected Systems
This issue affects the Switcorp Profiler – What Slowing Down Your WP plugin for WordPress, specifically all versions up to 1.0.0. Owners of sites using this plugin should review the plugin version in use and note that the security flaw is present in these releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, while the EPSS score of less than 1% suggests that the vulnerability is unlikely to be exploited at present. The flaw is not listed in CISA KEV, further indicating limited reported exploitation. An attacker would need only browser access to the Profiler page to trigger the vulnerability, implying a web-based attack vector that bypasses authentication. Once a plugin is reactivated, additional risks may arise depending on the plugin’s own security posture.
OpenCVE Enrichment
EUVD