Impact
The vulnerability is a missing authorization flaw in the Oshine Core plugin, identified as CWE-862. It allows an attacker to bypass normal access control checks and potentially gain administrative privileges over the WordPress site. This could result in the modification of site content, configuration changes, or installation of additional malicious plugins.
Affected Systems
The affected product is brandexponents Oshine Core, specifically versions through 1.5.5. All installations of this plugin that have not been upgraded past version 1.5.5 are at risk. Future versions beyond 1.5.5 are not mentioned in the available data, so it is prudent to assume that those versions may still be vulnerable if no patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity impact, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. It is likely to be exploited through direct interaction with privileged admin endpoints that have been improperly protected. An attacker with the ability to navigate to those endpoints could elevate privileges or perform unauthorized administrative actions. The overall risk is moderate, but the low exploitation probability reduces immediate urgency.
OpenCVE Enrichment
EUVD