Impact
The vulnerability is a missing authorization flaw in the Rustaurius Front End Users WordPress plugin, identified as CWE‑862. Because the plugin does not enforce proper role checks, an attacker could access and potentially manipulate content or functionality that should be restricted to higher‑privilege users. The impact is therefore an unintended elevation of privileges that can compromise the integrity of site content and user data.
Affected Systems
Addressable systems include any WordPress site running the Rustaurius Front End Users plugin, version 3.2.33 or earlier. All builds from the earliest release through 3.2.33 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, but the EPSS score of less than 1% suggests that real‑world exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, further indicating low exploitation risk. The likely attack vector is through the front‑end interface, where a user could request plugin URLs or use site forms without proper checks. An attacker who can submit crafted requests to the plugin endpoints could exploit the missing authorization to gain unauthorized access.
OpenCVE Enrichment