Impact
The Admin Management Xtended plugin suffers from a missing authorization check that allows users to access administrative functions without proper permission. This flaw, classified as CWE‑862, can enable attackers to elevate privileges or perform unintended administrative actions once they can reach the vulnerable code path.
Affected Systems
Vulnerable installations include the wpseek Admin Management Xtended WordPress plugin up to version 2.5.1. The issue applies to all releases from the plugin’s earliest available version through and including 2.5.1. The plugin is commonly used to manage administrator accounts in WordPress sites.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying it is not known to be widely exploited. Attackers would need access to the site’s web interface and some level of authenticated or unauthenticated access to trigger the flaw, making the attack vector likely web‑based and contingent on configuration errors.
OpenCVE Enrichment