Impact
The vulnerability is a missing authorization check in the Sovlix MeetingHub plugin, allowing an attacker to bypass intended access controls. By exploiting this flaw, a user could gain unauthorized access to plugin features, potentially viewing or modifying data beyond the scope of their role. The weakness aligns with CWE‑862, which emphasizes improper enforcement of access control policies.
Affected Systems
The affected product is the MeetingHub plugin for WordPress developed by Sovlix. Versions up to and including 1.23.9 are vulnerable; any installation of the plugin at these or earlier releases must be updated.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread, actively exploited attacks. Based on the description, it is inferred that the missing check can be triggered by any user interacting with the plugin’s endpoints, so both authenticated and potentially unauthenticated users may exploit the flaw depending on how the plugin is configured.
OpenCVE Enrichment