Impact
A missing authorization check in the WPLMS theme allows an attacker to bypass protected access levels and perform actions not intended for their role. The flaw results in unauthorized use of restricted plugin functionality, potentially exposing sensitive data or enabling further exploitation of the WordPress site. The vulnerability is categorized under CWE-862, which relates to improper authorization.
Affected Systems
VibeThemes WPLMS plugin for WordPress, versions from the earliest release through 4.970 are affected. Users running any supported installation of the theme that has not been updated past 4.970 are susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The issue is not listed in the CISA KEV catalog. Likely attack vectors involve crafting HTTP requests that target protected endpoints, or manipulating user roles within the WordPress admin console. The attacker would need knowledge of which capabilities are missing to exploit the weakness, and the conditions for successful exploitation are implicitly tied to the plugin’s default configuration.
OpenCVE Enrichment
EUVD