Impact
This vulnerability is a missing authorization flaw in the VeronaLabs WP SMS plugin for WordPress. Users lacking proper permissions can perform privileged actions normally reserved for administrators, such as modifying or deleting SMS templates or accessing sensitive settings. The weakness is classified as CWE‑862, indicating a failure in enforcing correct access control. Attackers could exploit this flaw to make unauthorized changes that may lead to data tampering or expose information within the WordPress site.
Affected Systems
The affected product is VeronaLabs WP SMS, with all releases up to and including version 7.0.1 impacted. Users running any of these versions on a WordPress installation are vulnerable.
Risk and Exploitability
The CVSS score of 5.4 reflects a moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation. Likely exploitation would occur through the web interface by authenticated users who should not have those capabilities; an attacker may trick a user or use a stolen credential to gain elevated permissions.
OpenCVE Enrichment