Impact
The vulnerability is a missing authorization flaw in the WordPress Team Manager plugin, which prevents proper enforcement of configured access control levels. Because of this, users lacking the appropriate permissions could access functions or data that should be restricted. The flaw is classified as CWE-862. The description does not detail whether the compromise requires authentication or how far the attacker could go, so conclusions about privilege escalation or data exposure are not supported by the disclosure.
Affected Systems
The affected product is Dynamic Web Lab Team Manager (WordPress wp-team-manager) for all versions up to and including 2.6.8. No specific release beyond 2.6.8 is mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation. No listing in the CISA KEV catalog means no confirmed widespread exploitation currently. The likely attack vector would be a web request to the plugin’s administrative endpoints, but the description does not confirm whether authentication is required. Therefore, it cannot be definitively stated whether unauthorized users could exploit the flaw without prior authentication.
OpenCVE Enrichment
EUVD