Impact
The vulnerability is a missing authorization flaw in the WebinarIgnition WordPress plugin. It allows users to trigger actions that should be restricted to higher privilege levels. This broken access control enables attackers to potentially modify webinar settings, view or delete content, or execute other administrative functions, thereby compromising the confidentiality, integrity, or availability of the WordPress site. The weakness is categorized as CWE‑862.
Affected Systems
Affected products are the WordPress WebinarIgnition plugin developed by the Saleswonder Team: Tobias. All releases up to and including version 4.06.04 are impacted. No specific patch versions are listed in the advisory, so the policy applies to any installation with a version identified as 4.06.04 or earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% reflects a low probability of exploitation, and the issue is not listed in CISA’s KEV catalog. The flaw can be exploited remotely through the WordPress web interface, and it does not require user interaction beyond normal access to the plugin’s administrative screens. Attackers who possess any authenticated user role, even those with limited privileges, can leverage the lack of proper access checks to elevate their privileges within the plugin.
OpenCVE Enrichment