Impact
Missing authorization in the Subscribe To Unlock plugin allows attackers to bypass its intended access controls. This flaw can lead to unauthorized acquisition of subscriber data or manipulation of subscription settings, potentially exposing sensitive user information. The vulnerability is classified as an access control weakness (CWE-862).
Affected Systems
All published releases of the wpshuffle Subscribe To Unlock plugin up to and including version 1.1.5. On WordPress sites that have installed any of these versions, the plugin’s endpoints lack the necessary checks to verify user roles before processing requests.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity level, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation as of the last update. It is not listed in CISA’s KEV catalog. The flaw is exploited by accessing the plugin’s protected endpoints without proper authentication, which is most likely a web‑based attack vector. An attacker who can reach the endpoint—whether as a site owner, administrator, or guest—could read or alter subscriber information.
OpenCVE Enrichment
EUVD